Skip to main content
Ernie
Explorer II
February 28, 2025
Question

FortiSIEM account locked due to excessive login failures

  • February 28, 2025
  • 2 replies
  • 1457 views

Hi Community,

 

Recently our FortiSIEM is flooded every 2 seconds with "System user account locked due to excessive login failures" by user SYSTEM(su). Which generates an Incident that locks out the user...

 

The Short Process Name is AppServer but the remarkable thing is, that the request comes from it's own IP address (=192.168.1.1):

 

 

 

 

 

[root@FortiSIEM logs]# tail -f /var/log/httpd/ssl_request_log | grep 192.168.1.1 192.168.1.1 - - [28/Feb/2025:15:07:17 +0100] "GET /phoenix HTTP/1.1" 301 180 "-" "-" 192.168.1.1 - - [28/Feb/2025:15:07:17 +0100] "GET /phoenix/ HTTP/1.1" 302 190 "-" "-" 192.168.1.1 - - [28/Feb/2025:15:07:17 +0100] "GET /phoenix/login.html HTTP/1.1" 200 2025 "-" "-" 192.168.1.1 - - [28/Feb/2025:15:07:18 +0100] "GET /phoenix/rest/sync/task?custId=1&agentId=1&time=1740751638&phProcessName=phMonitorSupervisor HTTP/1.1" 200 112 "-" "-" 192.168.1.1 - - [28/Feb/2025:15:07:19 +0100] "GET /phoenix HTTP/1.1" 301 180 "-" "-" 192.168.1.1 - - [28/Feb/2025:15:07:19 +0100] "GET /phoenix/ HTTP/1.1" 302 190 "-" "-" 192.168.1.1 - - [28/Feb/2025:15:07:19 +0100] "GET /phoenix/login.html HTTP/1.1" 200 2025 "-" "-" 192.168.1.1 - - [28/Feb/2025:15:07:21 +0100] "GET /phoenix HTTP/1.1" 301 180 "-" "-" 192.168.1.1 - - [28/Feb/2025:15:07:21 +0100] "GET /phoenix/ HTTP/1.1" 302 190 "-" "-" 192.168.1.1 - - [28/Feb/2025:15:07:21 +0100] "GET /phoenix/login.html HTTP/1.1" 200 2025 "-" "-"

 

 

 

 

I can't seem to find out or block the IP, for example with an .htaccess file.

 

Has anyone got a clue on how to solve this?

2 replies

Secucard
New Member
July 16, 2025

Hi, we had it with 7.3.0 and now, with 7.4.0, even it got more worse. Same problem.

Can anyone from Fortinet help us?

Secusaurus
Contributor III
July 16, 2025

Hi @Ernie and @Secucard,

 

I see this issue usually in context with upgrades. The internal cluster passwords get changed/reset on cluster upgrades, so the workers trying to access the supervisor or even internal processes might not be able to connect to each other during an upgrade or after issues with the upgrade. It will have a mismatch if you run "phLicenseTool --showRedisPassword"

 

If this is not you issue, can you share more details/logs about the issue and your deployment scenario?

 

Best,

Christian

NSE8 | Fortinet Advanced MSSP Partner