FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
Andy_G
Staff
Staff
Article Id 197581

Description

Summary of Topic

This article will briefly instruct you on setting up event data archive on the AO portal if event data archive is failing with following error as attached screen shot:

phDataManager:Event DB Archive directory /<IP>/mnt/Archive/ in not accessible

agodwin_FD39594_tn_FD39594-1.jpg


Solution Steps

1. Set up mount on AO shell as user "admin".

2. Logon to AO portal as admin
3. Go to Admin > Event DB Management and click on Archive policy tab
4. Specify the event archive directory - event data files would be archived in this location. Please note,  this should be the file system path on the AO, it's not the path on your NFS server so that no need to specify the NFS server host name or IP.
5. Click Apply
6. Define per-organization archive data management policy
     a. Click New
     b. Specify organization name (this is meaningful for AO-SP where a per-organization policy can be specified)
     c. Specify number of days for which events would be archived

 

Additional Information

 

Version Application

All

 

 

Contributors