Log storage and forwarding
In its standalone configuration, a firewall has somewhere between a few terabytes of storage on high-end devices and a few gigabytes on low-end devices for logs. This space then has to be split up among all the different log databases, such as Traffic
, Threat
, WildFire
, and several others. This could cause a skewed perception of how much log storage is actually available and, combined with high traffic volume, this could lead to the system having only enough storage for a couple of days' worth of logs.
To review the current log capacity and what percentage of the capacity has been assigned to individual databases, check Device | Setup | Management | Logging and Reporting Settings. You can change how much space is reserved for each log database by changing the percentage next to each log database, as you can see in the following screenshot. Keep an eye on the total allocation near the bottom left of the screen: