Skip to main content
koolishami
Staff
May 21, 2025

Troubleshooting Tip: Linux Agent installed successfully, but does not appear in CMDB or shows as 'Disconnected' in CMDB

  • May 21, 2025
  • 0 replies
  • 842 views
Description This article describes how to resolve an issue where the FortiSIEM Linux Agent shows a 'Disconnected' status on the Supervisor, or when the agent registers successfully but does not appear in the CMDB.
Scope

FortiSIEM v7.0.X, v7.1.X, 7.2.X, Linux host OS: RHEL 9.5 or Rocky Linux 9.5.

Solution

Root cause:

On some Linux operating systems, SELinux (Security-Enhanced Linux) is enabled by default in Enforcing mode.

This may block the FortiSIEM Linux Agent (FSM) from writing its template file on the host system.

 

As a result:

  • The agent is unable to determine which log types to collect.
  • No logs are sent to the Supervisor.
  • The agent status remains 'Disconnected'.

 

Workaround:

Temporarily switch SELinux to Permissive mode. Once the Linux Agent becomes active and starts sending logs, revert SELinux to Enforcing mode. The agent will remain in a 'Running Active' state.

 

Change SELinux status to 'permissive' using the following command:

 

setenforce 0

 

For more information, refer to the official Red Hat documentation: Changing SELinux to permissive mode.

 

Solution:

Upgrade Supervisor, collector and Linux agent to version 7.3.2 or above.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!