Fortinet black logo

FortiAnalyzer-BigData log export CLI

FortiAnalyzer-BigData log export CLI

This section describes how to use fazbd-log-export, the FortiAnalyzer-BigData log export Command Line Interface (CLI) tool, and contains references for all fazbd-log-export commands.

fazbd-log-export is available on the cluster controller (see Connect to the FortiAnalyzer-BigData CLI) and is the command used to export logs from the FortiAnalyzer-BigData log database. It allows you to perform various operations related to log export sessions.

Syntax

fazbd-log-export <command>

Commands

Command

Description

init

Initialize a log export session with specified parameters such as ADOM, log type, device type, device IDs, start and end dates, and log file format (CSV or Parquet).

start <session_id>

Start or resume a log export session with the given session ID.

pause <session_id>

Pause a log export session with the given session ID.

force-stop

Force stop the running session and release the lock.

status <session_id>

List all log export sessions or retrieves the status of a specific session.

push <session_id>

Transfer the exported log files to an external target server using SCP or FTP. Requires a session ID.

close <session_id>

Close a log export session with the given session ID and clear all the resources.

FortiAnalyzer-BigData log export CLI

This section describes how to use fazbd-log-export, the FortiAnalyzer-BigData log export Command Line Interface (CLI) tool, and contains references for all fazbd-log-export commands.

fazbd-log-export is available on the cluster controller (see Connect to the FortiAnalyzer-BigData CLI) and is the command used to export logs from the FortiAnalyzer-BigData log database. It allows you to perform various operations related to log export sessions.

Syntax

fazbd-log-export <command>

Commands

Command

Description

init

Initialize a log export session with specified parameters such as ADOM, log type, device type, device IDs, start and end dates, and log file format (CSV or Parquet).

start <session_id>

Start or resume a log export session with the given session ID.

pause <session_id>

Pause a log export session with the given session ID.

force-stop

Force stop the running session and release the lock.

status <session_id>

List all log export sessions or retrieves the status of a specific session.

push <session_id>

Transfer the exported log files to an external target server using SCP or FTP. Requires a session ID.

close <session_id>

Close a log export session with the given session ID and clear all the resources.