Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
peterjhd1218
New Contributor

FortiAnalizer Historical logs Problem

Hi, I have a problem with the display of historical logs, the real time works fine but when i try to display the logs for example of the last 30 minutos it show me "no records found", but the logs has been saved and I have logs from moths ago

The problem that I see right now is that the CPU is always at 100%

 

I execute the command "execute top" and it show me next output, according to this the part of wa is consuming a lot of CPU,     i´ve read some documentation and this part it means " waiting por I/O" but I don´t now what it means

 

Cpu(s): 30.5%us,  5.3%sy,  0.0%ni,  0.0%id, 63.2%wa,  0.0%hi,  1.0%si,  0.0%st

 

Version: v5.2.7

 

HElp

 

Regards

2 REPLIES 2
chall_FTNT
Staff
Staff

Best to open a support ticket.  But if %wa (IO wait) is > 20%, by default SQL insertion (aka indexing) will not happen (since that is supposed to be a background task) & in this case, you will never see Historical Logs (that data is taken from the SQL database).  You either have disk performance issues or possibly the incoming log rate is too high for that model.

Chris Hall
Fortinet Technical Support
emnoc
Esteemed Contributor III

Dumb question are you  doing real-time or upload for the logs into the FAZ?

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors