1. FortiAnalyzer Administration Guide 7.4.2
Page 161
Section: "Log files".
The guide states: "Logs are indexed to the SQL database for analytic support. Analytics logs are also referred to as indexed logs." This directly supports option D.
It also defines other log states: "The active log file is the log file that is currently receiving logs from the connected devices." (Refuting A) and "When a log file is rolled over
it is compressed to the .gz format and archived." (Refuting B).
2. FortiAnalyzer Administration Guide 7.4.2
Page 162
Section: "Log rolling".
This section describes log rolling as a process: "Log rolling saves the active log file and starts a new active log file when the active log file reaches a specific size or at a scheduled time." This confirms that option C is a process
not a log type.