Multiple tiers high availability
Description
Log collection, spread across multiple layers:
-
Collector layer: first layer dedicated to log collection, archiving and forwarding to the analyzer layer.
-
Analyzer layer: second layer deployed in high availability and focused on analytics and reporting activities.
The FortiAnalyzer in the analyzer layer can be deployed in high availability to ensure real-time redundancy and log/data synchronization.
Limitations
-
Analytics sustained log/sec rate limited to single device capacity.
-
Collectors only provide historical log view (no reporting or FortiView).
Use case
Large international companies with regional sites. The collector tier is regionally deployed to establish an OFTP connection to each managed device and to consolidate logs regionally before forwarding them to the analyzer tier. If the connectivity between the collector and analyzer tier is unavailable, logs can be buffered at the collector level.