Skip to main content
kmo
Staff
Staff
November 9, 2022

Technical Tip: Load Balancing of metrics when monitored via OnSight Cluster

  • November 9, 2022
  • 0 replies
  • 588 views
Description This article describes two different scenarios in which OnSight load balancing can occur. 
Scope FortiMonitor, OnSight.
Solution

Scenario 1.

The first scenario describes an OnSight in a high-availability (HA) cluster performing a temporary failover. 

 

Pre-requisites:  

  1. The total metric count (SNMP, Fabric, and Network) of both the OnSights is the same.
  2. The instance agent has 'Monitoring Location' as one of the OnSight in the HA pair. 

 

A few scenario considerations: 

  1. The first OnSight name can be considered as 'OnSight 1' and the second OnSight as 'OnSight 2'.
  2. One of the OnSights is not able to sync, and there is an OnSight heartbeat (HB) alert.  

 

For current instances and metrics that have 'Monitoring Location' set to OnSight 1, there will be a failover of metrics performed if OnSight 1 is unable to sync (or there is an OnSight HB alert).

 

When this incident occurs, the HA cluster will automatically failover to the next available OnSight temporarily in the backend.

 

As a result, the 'Monitoring Location' of the instance will not be changed on the user interface despite OnSight 2 conducting the checks instead of OnSight 1.

Once OnSight 1 can sync successfully again, the checks will be moved back to OnSight 1.  

 

Scenario 2.

The second scenario explains when an OnSight will load balance due to metric count. 

 

Pre-requisites:  

OnSights must be in the same HA pair on the OnSight group.  

 

A few scenario considerations:  

  1. The total metric count (SNMP and Network) of both the OnSights is the same. 
  2. The first OnSight name can be considered as 'OnSight 1' and the second OnSight as 'OnSight 2'.
  3. Both OnSights are active, and there are no OnSight HB alerts.

 

For new SNMP, Fabric, or Network instances that are being onboarded and have 'Monitoring Location' set to OnSight 1 (at the instance and metric level), backend checks will compare the total number of checks for each OnSight. Users can confirm the metric count between cluster members by visiting Monitoring -> OnSights and validating that the metric count is even across all members.

 

If the difference between OnSight 1 and OnSight 2 is significant, the FortiMonitor OnSight will try to load balance the metrics.

 

This means that the monitoring location at both the server and metric level will be switched to OnSight 2 permanently. 

Unlike Scenario 1, this change in monitoring location is formal, as this action is not considered to be temporary. 

 

A few key points to remember related to Scenario 2:

  1. Currently, FortiMonitor calculates the total metric count for SNMP, Fabric, and Network checks on each Onsight within the HA group, and then load balances the metrics.
  2. FortiMonitor checks every two hours to identify if there is a need for the load balancing of metrics (SNMP, Fabric, and Network) within the OnSight HA cluster.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!