Configuring log storage policy
The log storage policy affects the logs and databases of the devices associated with the log storage policy.
If you change log storage settings, the new date ranges affect Analytics and Archive logs currently in the FortiAnalyzer device. Depending on the date change, Analytics logs might be purged from the database, Archive logs might be added back to the database, and Archive logs outside the date range might be deleted. |
To configure log storage settings:
- Go to System Settings > ADOMs
- Double-click an ADOM. Scroll to the log storage policy sections at the bottom of the Edit ADOM pane.
Aternatively, you can right-click on an ADOM and then select Edit from the shortcut menu, or select the ADOM and then click Edit in the toolbar.
- Configure the following settings, then click OK.
Data Policy
Keep Logs for Analytics
Specify how long to keep Analytics logs.
If set to 0, the Analytics logs will be kept for unlimited days.
Keep Logs for Archive
Specify how long to keep Archive logs. Make sure your setting meets your organization’s regulatory requirements.
If set to 0, the Archive logs will be deleted after rolling. Note that the rolled log files will be kept until the next retention policy check, which occurs every twelve hours.
Disk Utilization
Allocated
Specify the amount of disk space allotted. See also Disk space allocation.
Analytics: Archive
Specify the disk space ratio between Analytics and Archive logs. Analytics logs require more space than Archive logs. Select Modify to change the setting.
Alert and Delete When Usage Reaches
Specify the percentage of allotted disk space usage that will trigger an alert messages and start automatically deleting logs. The oldest Archive log files or Analytics database tables are deleted first.