Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tonifan
New Contributor

Fortianalyzer exceeds the quota of defined archive logs

Hello,

in my FAZ an ADOM exceeds the quota of defined archive logs without deleting the oldest ones. How can I fix it? Maybe a Rebuild of the data-base? Or trying to increase the value of Keep Logs for Archive compared to the days storaged? thankyou

5 REPLIES 5
brazz_FTNT
Staff
Staff

Hello, 

 

What is the FAZ version ?

how many devices are connected to FAZ ? and actively sending logs to FAZ ?

Thanks 

tonifan

v6.0.2-build0205 180813 (GA)

30 devices connected, and actively sending logs.

I did a rebuild of the global data-base and I've changed the Archive Config Days.

now after 10 days I get this:

199/191(104%)

this means that the log collection exceded the quota

 

maybe I have to open a ticket....

brazz_FTNT

Hello, 

 

 

Can you also please  check the log file rolling size? BY default is set to 200M.

 

It would be the best if you open up a case with Fortinet Support.

 

 

Thanks 

tonifan

yes, it is 

Roll log file when size exceeds 200M.

 

I'm opening a ticket.

tonifan

ticket closed!

 

this is not an issue, this is the normal work of faz.

until the Analytics Usage (Max) and the Archive Usage (Max) are reached the relative logs are collected, also if the configured days are exceeded.

 

good

Labels
Top Kudoed Authors