▲
31
FortiGate logid 0000000013 is 90% of my log volume. Can I drop it?
session close records, hundreds of thousands a day, eating the whole ingest budget. any reason to keep the individual lines
session close records, hundreds of thousands a day, eating the whole ingest budget. any reason to keep the individual lines
Drop them, but count them first.
That logid with
type="traffic" subtype="forward" action="close"is a session ending normally. Nobody has ever investigated an incident by reading one. The value is entirely in aggregate: which networks your users reach, how much moved, when that changed.So do not store the lines, do keep counters for destination country, service, bytes.
One thing worth checking while you are in there. Are you logging denies at all? A lot of FortiGates are set up to log accepts and not blocks, which is exactly backwards. Blocked traffic is the interesting half and a fraction of the volume.