nerdexam
Fortinet

NSE4 · Question #293

When performing a log search on a FortiAnalyzer, it is generally recommended to use the Quick Search option. What is a valid reason for using the Full Search option, instead?

The correct answer is A. The search items you are looking for are not contained in indexed log fields. FortiAnalyzer's Full Search option is used when the desired search criteria or specific details are not contained within the indexed log fields used by Quick Search.

Submitted by devops_kid· Apr 18, 2026Logging and Monitoring

Question

When performing a log search on a FortiAnalyzer, it is generally recommended to use the Quick Search option. What is a valid reason for using the Full Search option, instead?

Options

  • AThe search items you are looking for are not contained in indexed log fields.
  • BA quick search only searches data received within the last 24 hours.
  • CYou want the search to include the FortiAnalyzer's local logs.
  • DYou want the search to include content archive data as well.

How the community answered

(36 responses)
  • A
    92% (33)
  • C
    6% (2)
  • D
    3% (1)

Why each option

FortiAnalyzer's Full Search option is used when the desired search criteria or specific details are not contained within the indexed log fields used by Quick Search.

AThe search items you are looking for are not contained in indexed log fields.Correct

FortiAnalyzer's Quick Search is optimized for speed by querying only a subset of indexed log fields. When the required information is located in non-indexed fields or requires a deeper scan of the raw log content, the Full Search option is necessary.

BA quick search only searches data received within the last 24 hours.

Quick Search is not limited to data received within the last 24 hours; it can search across the entire log dataset, albeit only on indexed fields.

CYou want the search to include the FortiAnalyzer's local logs.

Both Quick Search and Full Search are designed to search across the FortiAnalyzer's stored logs, including logs received from FortiGates and potentially its own system logs, not exclusively differentiating local logs.

DYou want the search to include content archive data as well.

Content archive data (e.g., email or web content archives) is typically searched using specialized archive features, not through the general log Quick or Full Search functionality.

Concept tested: FortiAnalyzer log search types

Source: https://docs.fortinet.com/document/fortianalyzer/7.4.0/administration-guide/524310/log-view

Topics

#FortiAnalyzer#Log Search#Indexed Logs#Full Search

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice