Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SM31
New Contributor

FortiGate log retention when FAZ down behavior

Hi folks,

 

We're using FGT-1500D cluster running FortiOS v5.2.6.

We have disabled memory logging and disk logging. 

We upload logs in realtime to two FortiAnalyzer and we're wondering how things will go in case the two FAZ go down:

1/ Do we will lose new logs?

2/ Will the FortiGate store logs in a buffer waiting for one FAZ to come back alive?

3/ If yes to #2, does the FortiGate keep a trace of logs sent to one FAZ and the ones not the other FAZ?

4/ If yes to #2, what is the long retention capacity (buffer size)? Can it be adjustable? 

 

In other words, is it possible to keep logging on FGT's disks when FAZ are unavailable and to send all the buffered logs, during FAZ downtime, to the FAZ when they become available while keeping logs consistency on both FAZ?

 

Thanks.

4 REPLIES 4
Jeff_FTNT
Staff
Staff

Yes, FGT can buffer some log to memory.

CLI:config sys fortianalyzer setting/set conn-timeout      xx/

When fail to access FAZ and wait  conn-timeout is reached , FGT will buffer log to memory, when the buffer is full, log will be droped.

The buffer size is  not  be adjustable, depend on your FGT memory size.

When connection to FAZ is recover, it will upload log in buffer to FAZ.Thanks.

SM31
New Contributor

Hi Jeff,

 

Thanks four inputs.

Just for information, likely the CLI command is in "config log fortianalyzer setting" (and not config sys fortianalyzer setting).

Still few questions please: 

- Is it possible to buffer log to disk instead of into the memory?

- Do you know the memory buffer size for 1500D model?

- When the connection to one FAZ is recovered and is not with one other FAZ, does the FGT keep a consistence of log transferred to one FAZ and those which are not the other in the eventuality where one FAZ does not recover in the same time as the other one? Or potentially the amount of buffered logs will not be the same on the two FAZ?

 

Thanks again. 

AndreaSoliva
Contributor III

Hi

 

as of my information: - Is it possible to buffer log to disk instead of into the memory?

 

--> Clearly NO way

- Do you know the memory buffer size for 1500D model?

 

--> Memory Logging size whihch means 10 % of Memory

- When the connection to one FAZ is recovered and is not with one other FAZ, does the FGT keep a consistence of log transferred to one FAZ and those which are not the other in the eventuality where one FAZ does not recover in the same time as the other one? Or potentially the amount of buffered logs will not be the same on the two FAZ?

 

--> From my point of view same way meaning keeps in the buffer as soon as it comes available will be transfered.

 

hope this helps

 

have fun

 

Andrea

AlexFeren

Is it possible to know how much of Fortigate's buffer size is actually utilised at any one time during loss of contact with FortiAnalyzer?

Is it possible to know how many log events were lost during loss of contact with FortiAnalyzer?

Labels
Top Kudoed Authors