View all questions & answers for the NSE 5 - FortiAnalyzer 7.4 Analyst Exam Materials exam


Question 25 Discussion

After generating a report, you notice the information you were expecting to see is not included in it. What are two possible reasons for this scenario? (Choose two answers)

  • A. You enabled auto-cache with extended log filtering.
  • B. The logfiled service has not indexed all the expected logs.
  • C. The logs were overwritten by the data retention policy.
  • D. The time frame selected in the report is wrong.
Correct Answer: C,D

Brave-Dump Clients Votes

CD 100%

Comments



Ibrahim Eldesoki 2025-04-06 22:46:06

Selected Answers: C, D


What happens if you run reports and they are empty or don’t contain the desired information? Here are some troubleshooting tips: - Check the time frame that is covered by the report. This is listed within the report itself. - Compare the time frame to the logs and verify that you have the log file for the time in question. - Verify that you have logs from the time the report was run and from the device that the report was run for. A common issue is caused by logs being overwritten too quickly. The result is that the logs needed for the report are overwritten and, as such, are unavailable once the report is run. In this case, the solution is to increase the disk quota to ensure that logs are retained longer. - Test the dataset in question and verify that it is retrieving the correct information. If it isn’t, then troubleshoot the SQL query itself, because it is probably the dataset that contains the error. - Check your report advanced settings. A setting such as user obfuscate can result in abnormal usernames in the report. Also verify the filters attached to a report. It is possible that your filter is filtering out the desired logs.