A substation FortiGate is configured to log only to its own local disk, with no external log destination. What operational risk does this configuration carry that is specific to a remote, unstaffed site?
Select an answer to reveal the explanation.
Short Explanation
Local disk on a field device is finite, and once it fills up the oldest entries just get overwritten to make room for new ones, with no external copy sitting anywhere else, that older history is simply gone. At an unstaffed site, nobody's there to notice or intervene before that happens.
Full Explanation
When a FortiGate logs only to local disk, storage capacity is limited and the device cycles by overwriting its oldest entries once that capacity fills, so any log data beyond the local retention window is permanently lost unless a copy exists somewhere else, a risk that's magnified at a remote, unstaffed substation where nobody is present to notice the disk filling or to intervene before older data rolls off. Logging configuration has no effect on the FortiGate's ability to pass traffic; these are entirely separate subsystems, and traffic forwarding continues regardless of local logging status. FortiGuard signature updates are governed by license and connectivity to Fortinet's distribution network, not by where log data happens to be stored. SNMP polling is an independent monitoring protocol that keeps functioning whether logs go to local disk, an external destination, or both. The practical mitigation and check: forwarding logs to an external destination like a syslog server or FortiAnalyzer removes the dependency on local capacity, and periodically confirming how much local retention window remains before rollover is a reasonable interim check if forwarding isn't yet in place.