Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
badrg
New Contributor II

Loss in forwarding logs

Hello,

 

I would like to have confirmation if possible (I'm a novice in the field).

 

I have this message "Log-forward 'ld-xxxxxxx' lag behind 99.92%, discarded 9551454767149537bytes, every 10min and I think the FAZ can't forward all logs to ELK. Can anyone confirme my thinking 

 

Even in the graph < Receive Rate vs Forwarding Rate > I can see that number of receiving log is heigher than the forwarding one.

 

Thank you for your help.

One Piece is the best
One Piece is the best
1 Solution
dbu

Yes both points are correct. 
If issue is not on the FAZ resources then probably the Firewall is applying some traffic shaping which might drop the traffic

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

4 REPLIES 4
dbu
Staff
Staff

Hi @badrg ,

Is there any traffic shaping policy in place which can drop the traffic ? 
Keep in mind that log forwarding needs a lot of resources(CPU/MEM), have you checked the minimum system requirements ? 
If this is a new setup it is worth verifying the configuration.
Some troubleshooting commands which might help find your issue:
diag test application logfwd 1
diag test application logfwd 3
diag test application logfwd 4
diagnose test connection syslogserver <server -name>

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
badrg
New Contributor II

Hi @dbu 

Thank you for your time and your respond.

for now I don't search to troubleshoot, but firt to confirm what I suspect.

  1. The message event "lag behind 99.92%, discarded xxxxxxxx bytes" I would like to know the real meaning, from my thinking it's a problem in FAZ resources that impacte the forwarding process.
  2. The graph "Receive Rate vs Forwarding Rate" it's represente the real number of receiving and forwarding log?

 

and for your question, yes they are a FW in the middle and the flow are authorized.

 

One Piece is the best
One Piece is the best
dbu

Yes both points are correct. 
If issue is not on the FAZ resources then probably the Firewall is applying some traffic shaping which might drop the traffic

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
badrg
New Contributor II

Thank you @dbu 

One Piece is the best
One Piece is the best
Labels
Top Kudoed Authors