Skip to main content
KarlH
Explorer II
October 9, 2024
Solved

How to correctly re-register a Collector all ph procs are down.

  • October 9, 2024
  • 4 replies
  • 2777 views

! collector was registered at one point

lost the password

updated password then tried to run phtools start all

prcos are down and will not come up.

 

/opt/phoenix/bin/phProvisionCollector --add admin 'biglong pw' siem vendor org
Continuing to provision the Collector
Failed to register collector!
Cause:
The organization "130862006-vendor" has already registered a collector with name "collector name"

 

(But we had to change the credentials) 

Do these procedures still apply  to re-register a collector?  after getting the above error  , all their ph procs are down. 

 

:1. SSH to FortiSIEM Supervisor

2. Enter the following command to login into PSQL:        #psql -U phoenix phoenixdb 

   3. Update the PSQL Database:        =>ph_sys_collector set natural_id='' where name=<collector name>;  

  4. Quit PSQL:        =>\q   

 5. Re-register the Collector to Supervisor. Find in the related articles bellow "How to register a Collector or Super".    Revised:
    In step 3 full synxax => update ph_sys_collector set natural_id = '' where name = 'collector name'

 

 

phtools --start all
[PH_MODULE_LOCAL_CONFIG_LOADED]:[eventSeverity]=PHL_INFO,[procName]=phtools,[fileName]=phConfigLoader.cpp,[lineNumber]=168,[configName]=global,[phLogDetail]=Module loaded local config successfully
[PH_LICENSE_ERROR]:[eventSeverity]=PHL_ERROR,[procName]=phtools,[fileName]=phInstalledLicense.cpp,[lineNumber]=170,[errorString]=License Error: Please request new license from support, thanks!,[phLogDetail]=License error, please contact support.

 

 

Is it  a License issue? Do we investigate the phoenix log?

 

    Best answer by premchanderr

    Hi @KarlH ,
    This is the command to update:
    # /opt/phoenix/bin/phProvisionCollector --update <user> '<password>' <Super IP or Host> <Organization> <CollectorName>

    For delete there is no command. 

    Before deleting a collector, we must ensure no devices are pointing to this collector in CMDB.

    1. CMDB > Devices > Discovered by > Select the collector we want to delete from the drop-down.
    2. If devices are showing up under this collector, that is the root cause of this error.
    3. Please move those devices to a different collector.
    4. Select the device > Edit > Collector > Select a different collector from the drop-down.
    5. If there is no device under the collector, now you try to delete the collector from GUI. Go to Organization > Edit the org > select collector and delete. 

    4 replies

    kcanalichio
    New Member
    October 9, 2024

    You can try using the phProvision --update to re-register.  Otherwise get with TAC or rebuild the collector.

    premchanderr
    Staff & Editor
    Staff & Editor
    October 10, 2024

    Hi,

    Error: The organization "130862006-vendor" has already registered a collector with name "collector name"

     

    You would have to use --update or delete "130862006-vendor" collector first before re-install.

    KarlH
    KarlHAuthor
    Explorer II
    October 10, 2024

    HI what is the complete command please?   phProvision -delete 130862006-vendor ?

    and then the follow up command?  would be the ProvisionCollector command a

     

    and following the phtools --start all?

     

    Will this allow the procs to start then?

    premchanderr
    Staff & Editor
    Staff & Editor
    October 11, 2024

    Hi @KarlH ,
    This is the command to update:
    # /opt/phoenix/bin/phProvisionCollector --update <user> '<password>' <Super IP or Host> <Organization> <CollectorName>

    For delete there is no command. 

    Before deleting a collector, we must ensure no devices are pointing to this collector in CMDB.

    1. CMDB > Devices > Discovered by > Select the collector we want to delete from the drop-down.
    2. If devices are showing up under this collector, that is the root cause of this error.
    3. Please move those devices to a different collector.
    4. Select the device > Edit > Collector > Select a different collector from the drop-down.
    5. If there is no device under the collector, now you try to delete the collector from GUI. Go to Organization > Edit the org > select collector and delete. 
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!