Troubleshooting Tip: How to investigate why an incident is not triggered by a rule
Description
This article describes how to identify and investigate why an incident is not triggered by a rule.
Solution
Step-by-step guide:
- Identify the Rule that did not trigger and did not create an Incident.
- Ensure the Rule is active, and active for the Organization(s), if relevant.
- Assure that the Device involved is not in Maintenance mode (check Maintenance Calendar).
- Check the value of Allow Incident Firing On (Admin -> General Settings -> Monitoring page). If set to Approved Devices Only, then check in CMDB to make sure the device is Approved.
- Review the sub-pattern conditions.
- Review any exceptions defined in the rule.
- Run a historical search with the EXACT same criteria and Group By as the rule sub-pattern conditions and for the time window that incident should have been created.
-
Check for any matched events.
-
Check if the required number of matched events correspond to the rule
-
-
If exceptions are defined, then rerun historical search from 7 while adding the exclusion conditions to the criteria.
-
Check if there are any matched events.
-
Check for the number of matched events. Check if the queries return the required number of matched events from the rule.
-
Check if these matched events are within the time window of the rule.
-
-
Copy the original non-parsed "raw event" from an example event to the clipboard and use it to test the rule, using the Test Rule functionality (Note: this only works at Super level and with a rule that is inactive). Test whether it passes the test and creates an Incident.
-
If everything above supports that the rule should have fired and created an incident, create a support case and provide the following information:
- Raw event export from step 7.
- Rule export XML.
- Screenshot of any exceptions, if they are defined.
- Full AO logs from Super (and Workers if applicable)
See the related article below for more information.
Related article:
Technical Tip: How to retrieve logs from FortiSIEM VA and deliver them to support
