Skip to main content
RuiChang
Staff
Staff
April 9, 2025

Technical Tip: FortiSIEM http_client_peer_verify configuration

  • April 9, 2025
  • 0 replies
  • 294 views
Description

 

This article describes the best practice of configuring http_client_peer_verify in FortiSIEM.

 

Scope

 

FortiSIEM.

 

Solution

 

FortiSIEM contains a configuration to disable SSL verification for connection between the Supervisor and Collector. It can be found under the path below:

 

  1. Line 287 of '#vi /opt/phoenix/config/phoenix_config.txt'.
  2. Line 269 of '#vi /opt/phoenix/config/collector_config_template.txt'.

 

Note:

Both the Supervisor and Collector need to have the same configuration to ensure logs are uploaded successfully. If users notice Collector is unable to upload the logs after registering to the Supervisor, please troubleshoot withthe  command below:

 

  1. Check sniffer on CLI  of Supervisor:

 

# tshark -f “src <Collector IP>”

 

Note:

Users should see multiple RSTs from Collector due to SSL verification failure. '#curl -vk <Supervisor IP>' from Collector will be successful and it does not help troubleshoot these problems.

 

  1. Check logs on Collector:

 

# cat /opt/phoenix/log/phoenix.log |grep -i failed

 

Note:

Logs will show multiple 'Failed to upload Event Worker'.

In that case, users need to make sure both Supervisor and Collector are either enabled or disabled in the http_client_peer_verify option.

 

Related article:

Troubleshooting Tip: How to resolve Collector Event Upload errors with Self-signed Certificates installed on Workers

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!