Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ian_Harrison
New Contributor

Why are my log files been deleted?

Hi

 

On our FortiAnalyzer (v5.4) I see the following error messages:

 

Deleted 2 log files with total size 400.0MB to enforce the retention policy of Adom root.

 

However it is only using 47% of disk space.  I think it is to do with the retention policy but not sure what, any ideas please?

 

In settings it is set to only delete logs after it is 95% full.

 

OXP-A203-FAZ-01 # diag log device
Device Name          Device ID            Used Space(logs / quarantine / content / IPS) Allocated Space  Used%
KRD-A068-FG-01       FG3K2C3Z13800444      153.5GB( 153.5GB/   0.0KB/   0.0KB/   0.0KB) 3418.0GB         4.5% 
OXP-A203-FG-01       FG3K2C3Z13800352      209.9GB( 209.9GB/   0.0KB/   0.0KB/   0.0KB) 3418.0GB         6.1% 
Total: 2 log devices, used=363.4GB quota=6835.9GB
  
AdomName         AdomOID  Type                                 Logs                                                     Database
                                [Retention   Quota   UsedSpace(logs / quarantine / content / IPS) Used%]  [Retention   Quota      Used   Used%]
root             3        FGT     730days  2457.6GB  363.0GB( 363.0GB/   0.0KB/   0.0KB/   0.0KB) 14.8%     365days  3686.4GB 3137.1GB   85.1%
Total usage: 1 ADOMs, logs=363.0GB database=3138.5GB(ADOMs usage:3137.1GB + Internal Usage:1.4GB)
 
Total Quota Summary:
    Total Quota      Allocated        Available        Allocate%       
    7033.1GB         6144.0GB         889.1GB          87.4%
 
System Storage Summary:
    Total            Used             Available        Use%            
    7333.1GB         3511.6GB         3821.5GB         47.9%
 
Reserved space: 300.0GB ( 4.1% of total space).
Web: www.activatelearning.ac.uk Twitter: twitter.com/activate_learn Facebook: facebook.com/Activate-Learning
1 REPLY 1
Baptiste
Contributor II

I think it's because you can configure  maximum retention day, if they are older, they are deleted.

 

Based on the informations on your post, you keep log 365 days

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors