My FortiAnalyser is creaking with too many logs being generated per day. We have "all logging" turned on a lot of policies which we can probably reduce to UTM logs only - but I'd like to have a report of which policies are creating the most amount of logs so I can target them first.
Is there a report a a view I can enable to see which policies are generating the most amount of logs?
Thanks for all the replies. I have logged it with our support vendor who I've asked to raise with FortiNet (I'll log it directly if they don't but I have to jump through these hoops).
I have done a quick look at our biggest hitting policies on the FortiGates (we only have 2x HA pairs) - and looked for ones that have the largest number of hits and where Logging is enabled. I'll start with them.
I'm still going to look into the report option because it saves increasing our log licence, which is probably why it's not included out of the box ;)
3: and then tackle the one that has most hits per hour or day
I also do the above on a regular schedule to ID policies that are no longer used or have changed ( if the hits counts do not increase, that's a good chance the traffic has changed or policy, or is not no longer required )
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.