Troubleshooting Tip: FortiSIEM Windows Agents display an Event Status of Critical despite logs being received due to residual OMI onboarding artifacts
| Description | This article describes how to address an issue where Windows Agents in FortiSIEM continued to display an Event Status of 'Critical' despite successfully sending events. In some scenarios, these Windows Agents are also moved into the Inactive CMDB group, which impacts monitoring visibility and operations, and the condition can be traced to residual onboarding artifacts from OMI-based monitoring (Open Management Initiative), which can conflict with the native FortiSIEM Windows Agent health evaluation. |
| Scope | FortiSIEM v7.x+, Windows Agents that previously had OMI integrations. |
| Solution | This issue typically arises when Windows servers with FortiSIEM agents are reporting a Critical event status, even though logs are being received normally. As a result, these agents are automatically being placed into an Inactive CMDB group, which blocks correlation and downstream processing. The following symptoms have also been observed when this issue is occurring:
Root Cause:
FortiSIEM retains historical OMI monitoring artifacts, even after transitioning to native Windows Agent monitoring. These stale OMI entries result in:
The environment attempts to validate both OMI and native agent health. Since OMI is no longer valid, FortiSIEM interprets it as ongoing failure, keeping the Event Status Critical. For more information on OMI vs native agent, refer to the following documentation links:
Steps to Resolve the Issue:
Step 1 - Verify the Affected Hosts
Step 2 - Remove OMI Monitoring Traces
Step 3 - Remove OMI Credentials
Step 4 – Clean the CMDB Record
CMDB retains a stale binding of the device identity to previous OMI health metrics, which prevents status recalculation. Removing the CMDB entry forces FortiSIEM to rebuild a clean record.
Step 5 – Reinstall FortiSIEM Windows Agent
Validation: To validate that the issue is resolved, wait approximately 10 minutes after completing the above procedure and confirm that the Windows host reappears in the CMDB. Verify that the Event Status is Normal, that the host no longer belongs to the Inactive CMDB Group, and that logs are continuing to stream in normally.
If the issue is resolved, repeat the procedure for any additional Windows Agents affected by this issue.
Note: This issue is distinct from the case where Event Status remains 'Critical' following a FortiSIEM upgrade. In that scenario, simply deleting stale metrics is sufficient to resolve the issue, whereas this scenario requires the deeper cleanup and agent re-onboarding described above to resolve the OMI agent conflict.
Related documents: Troubleshooting Tip: How to troubleshoot collector issues Microsoft Windows Server via OMI/SNMP/WMI |
