What this article covers

A memory alert that consistently overlaps a FortiGuard update window should be correlated with update timing before unrelated configuration is changed.

ScopeLower-RAM FortiGate models, including FG-40F, FG-60F and FG-80F units, where conserve-mode alerts coincide with FortiGuard update activity.

Troubleshooting workflow

01

Use the minimal ISDB mode

The source recommends the minimal Internet Service Database definition mode.

config system global
    set isdb-optimization mini
end
02

Move updates outside peak periods

Stagger scheduled FortiGuard signature downloads outside the busiest operating window using config autoupdate schedule.

03

Review unused signature packages

Evaluate whether packages such as Industrial OT/IoT signatures are required in the deployed environment before disabling anything.

04

Prevent overlapping update attempts

Increase update retry intervals where repeated retries could overlap database download or compilation cycles.

05

Compare pre-update and post-update memory

Capture memory and conserve-mode state before the update, during the event and after compilation completes.

get system performance status
diagnose hardware sysinfo memory
diagnose hardware sysinfo conserve

Operational caution

Review before applying: Do not disable security content solely to reduce memory. Confirm that each package is unused and that the resulting protection level still meets policy.
Next step

Continue the evidence path

If memory does not return to baseline after the update, collect the high-memory evidence package.