Hi
On our FortiAnalyzer (v5.4) I see the following error messages:
Deleted 2 log files with total size 400.0MB to enforce the retention policy of Adom root.
However it is only using 47% of disk space. I think it is to do with the retention policy but not sure what, any ideas please?
In settings it is set to only delete logs after it is 95% full.
OXP-A203-FAZ-01 # diag log device
Device Name Device ID Used Space(logs / quarantine / content / IPS) Allocated Space Used%
KRD-A068-FG-01 FG3K2C3Z13800444 153.5GB( 153.5GB/ 0.0KB/ 0.0KB/ 0.0KB) 3418.0GB 4.5%
OXP-A203-FG-01 FG3K2C3Z13800352 209.9GB( 209.9GB/ 0.0KB/ 0.0KB/ 0.0KB) 3418.0GB 6.1%
Total: 2 log devices, used=363.4GB quota=6835.9GB
AdomName AdomOID Type Logs Database
[Retention Quota UsedSpace(logs / quarantine / content / IPS) Used%] [Retention Quota Used Used%]
root 3 FGT 730days 2457.6GB 363.0GB( 363.0GB/ 0.0KB/ 0.0KB/ 0.0KB) 14.8% 365days 3686.4GB 3137.1GB 85.1%
Total usage: 1 ADOMs, logs=363.0GB database=3138.5GB(ADOMs usage:3137.1GB + Internal Usage:1.4GB)
Total Quota Summary:
Total Quota Allocated Available Allocate%
7033.1GB 6144.0GB 889.1GB 87.4%
System Storage Summary:
Total Used Available Use%
7333.1GB 3511.6GB 3821.5GB 47.9%
Reserved space: 300.0GB ( 4.1% of total space).
Web: www.activatelearning.ac.uk
Twitter: twitter.com/activate_learn
Facebook: facebook.com/Activate-Learning
I think it's because you can configure maximum retention day, if they are older, they are deleted.
Based on the informations on your post, you keep log 365 days
2 FGT 100D + FTK200
3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
User | Count |
---|---|
2567 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.