Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Perrine
New Contributor

Removing logs for FortiAnalyzer via CLI

Dear all, I' m searching a way to remove many of my logs file from FortinAnalyzer but not all of them. I' ve got more than 1,000 logs files that have been uploaded to another server but for some reasons, at this time, I choose not to delete them after the upload. As the GUI asks for a confirmation before deleting each file, I let you imagine the time I should spend to delete my files. I tried to configure a Windows share to map it on my computer and delete the files by this way, but FA GUI says that the share can' t be set as read-write. I' m now searching for a command to execute using the CLI. Did you ever heard about that ? FYI, firmware version is v3.00 b0738 (MR7 patch 6) Thanks in advance for your help. Regards, Perrine
4 REPLIES 4
abelio
SuperUser
SuperUser

Hello and welcome,
I' m searching a way to remove many of my logs file from FortinAnalyzer but not all of them.
There' s no possibility to selectively remove the logs within you firmware version. CLI commands are also ' delete all' for this task. You could NFS mount the storage with RW mode but it' s not so practical to identify which logfile you want to remove and which not. This was solved in 4.0 firmware version; Patience, upgrading (carefully) or some type of script to automatize the task ....

regards




/ Abel

regards / Abel
Perrine
New Contributor

Hello Abel, Thank you for your answer. No upgrade is planned on my Fortinet architecture for the moment, so I' ll have to confirm that I really want to delete each file... Or could you tell me how to mount my share with RW access ? Regards, Perrine
abelio

you' ll need to setup a NFS server to do that; under linux is a very common task; BUT even done that, it' s not so easy establish which log file you want to remove and which want to keep by looking stored files. another approach, the ' argentinian way' , could be: -backup all the logs -delete all logs in the FAZ -delete what you want locally -restore to FAZ logs you want to preserve good luck

regards




/ Abel

regards / Abel
Perrine
New Contributor

Thank you Abel, I' ll probably ask my boss to backup everything, remove all logs from Fortianalyzer HD and reimport only needed logs. Thanks once again for your help.
Labels
Top Kudoed Authors