Fortinet white logo
Fortinet white logo

Administration Guide

Configuring log storage policy

Configuring log storage policy

The log storage policy affects the logs and databases of the devices associated with the log storage policy.

If you change log storage settings, the new date ranges affect Analytics and Archive logs currently in the FortiAnalyzer device. Depending on the date change, Analytics logs might be purged from the database, Archive logs might be added back to the database, and Archive logs outside the date range might be deleted.

To configure log storage settings:
  1. Go to System Settings > Storage Info.
  2. Double-click an ADOM. Scroll to the log storage policy sections at the bottom of the Edit ADOM pane.

    Aternatively, you can right-click on an ADOM and then select Edit from the shortcut menu, or select the ADOM and then click Edit in the toolbar.

  3. Configure the following settings, then click OK.

    Data Policy

    Keep Logs for Analytics

    Specify how long to keep Analytics logs.

    If set to 0, the Analytics logs will be kept for unlimited days.

    Keep Logs for Archive

    Specify how long to keep Archive logs. Make sure your setting meets your organization’s regulatory requirements.

    If set to 0, the Archive logs will be deleted after rolling. Note that the rolled log files will be kept until the next retention policy check, which occurs every twelve hours.

    Disk Utilization

    Allocated

    Specify the amount of disk space allotted. See also Disk space allocation.

    Analytics: Archive

    Specify the disk space ratio between Analytics and Archive logs. Analytics logs require more space than Archive logs. Select Modify to change the setting.

    Alert and Delete When Usage Reaches

    Specify the percentage of allotted disk space usage that will trigger an alert messages and start automatically deleting logs. The oldest Archive log files or Analytics database tables are deleted first.

Configuring log storage policy

Configuring log storage policy

The log storage policy affects the logs and databases of the devices associated with the log storage policy.

If you change log storage settings, the new date ranges affect Analytics and Archive logs currently in the FortiAnalyzer device. Depending on the date change, Analytics logs might be purged from the database, Archive logs might be added back to the database, and Archive logs outside the date range might be deleted.

To configure log storage settings:
  1. Go to System Settings > Storage Info.
  2. Double-click an ADOM. Scroll to the log storage policy sections at the bottom of the Edit ADOM pane.

    Aternatively, you can right-click on an ADOM and then select Edit from the shortcut menu, or select the ADOM and then click Edit in the toolbar.

  3. Configure the following settings, then click OK.

    Data Policy

    Keep Logs for Analytics

    Specify how long to keep Analytics logs.

    If set to 0, the Analytics logs will be kept for unlimited days.

    Keep Logs for Archive

    Specify how long to keep Archive logs. Make sure your setting meets your organization’s regulatory requirements.

    If set to 0, the Archive logs will be deleted after rolling. Note that the rolled log files will be kept until the next retention policy check, which occurs every twelve hours.

    Disk Utilization

    Allocated

    Specify the amount of disk space allotted. See also Disk space allocation.

    Analytics: Archive

    Specify the disk space ratio between Analytics and Archive logs. Analytics logs require more space than Archive logs. Select Modify to change the setting.

    Alert and Delete When Usage Reaches

    Specify the percentage of allotted disk space usage that will trigger an alert messages and start automatically deleting logs. The oldest Archive log files or Analytics database tables are deleted first.