What does the data point at 14:35 tell you?

View the exhibit.

What does the data point at 14:35 tell you?
A . FortiAnalyzer is dropping logs.
B . FortiAnalyzer is indexing logs faster than logs are being received.
C . FortiAnalyzer has temporarily stopped receiving logs so older logs’ can be indexed.
D . The sqlplugind daemon is ahead in indexing by one log.

Answer: D

Explanation:

Logs are received then they are indexed, no logging server in the world can index logs faster than they are received. When FAZ receives raw logs, they are inserted

(indexed) by the SQL database and the sqlplugind daemon, this graph shows that FAZ received 3 logs and sqlplugind indexed 4.

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments