FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
kjiye
Staff
Staff
Article Id 261593
Description This article explains why FortiGate only retrieves 1-hour logs when trying to view FortiAnalyzer logs.
Scope FortiAnalyzer 7.0.4 or above.
Solution If the FortiAnalyzer has a lot of historical logs, the FortiGate GUI forward traffic log page can take a while to load unless there is a specific filter for the time range.
Regarding this, starting with FAZ 7.0.4, it has been changed to allow the checking of logs in increments of 1 hour only for logs for which no filter is specified.
When a request to check logs from FortiAnalyzer in FortiGate does not have a time-related condition, the scope for the Last 1 Hour is automatically added to the filter.
So, to check logs older than 1 hour, a time-related filter is required.