Skip to main content
HarveyRebelo
Staff
Staff
July 17, 2026

Technical Tip: Troubleshooting FortiEDR-Core and FortiEDR-Aggregator Disconnection

  • July 17, 2026
  • 0 replies
  • 29 views

Description

This article describes the troubleshooting steps for resolving the disconnection issue between FortiEDR-Core and FortiEDR-Aggregator to FortiEDR Manager. The user may encounter this issue after a power outage or when the destination rejects the connection from the FortiEDR-Core and FortiEDR-Aggregator.

Scope

FortiEDR.

Solution

To troubleshoot the disconnection issue of FortiEDR-Core and FortiEDR-Aggregator, follow these steps:

  1. Check the connectivity to the FortiEDR Manager URL from the servers.


Linux:

telnet <hostname_or_ip> <port>


Windows:

telnet <hostname_or_ip> <port>


If the telnet connection fails, make sure that it is possible to reach the URL/IP address via ping (to discard any network trouble). If it is possible to reach via ping, open a ticket to Fortinet TAC Support to request Server (Core/Aggregator) public IP aggregation on the Whitelist.


Verify the logs to identify any errors or issues related to the disconnection.

  1. Make sure the Core/Aggregator version is compatible with FortiEDR Manager: Technical Tip: FortiEDR - Latest Release Version Chart & EOL Details.

  2. If the issue persists, collect the Server logs and share it to a TAC Engineer.


Aggregator:

tar -cvf aggregator_logs.tgz /opt/FortiEDR/aggregator/tmp/


tar -cvf nginx_logs.tgz /var/log/nginx/  


tar -czvf agg_logs.gz /opt/FortiEDR 


Core:

fortiedr stop


tar -czvf core_logs.gz /opt/FortiEDR/core


/opt/FortiEDR/core/bin/NsloCoreService --support


fortiedr start

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!