FortiEDR Manager restarted unexpectedly and Core/Aggregator components disconnected
I need help understanding an unexpected FortiEDR Manager restart.
We observed the following event:
Component: Manager
Component Name: Fortinet
Description: Server was restarted
Before this event, several FortiEDR components changed state to Disconnected:
XX:XX:XX - Aggregator [aggregator-cloud] changed to Disconnected
XX:XX:XX - Core [core-cloud] changed to Disconnected
XX:XX:XX - Core [fortiedr-core-jumpbox-onprem] changed to Disconnected
XX:XX:XX - Warning: The following connectors will become inactive: Firewall FW (name)
Then the services recovered after 20 seconds:
YY:YY:YY - Manager: Server was restarted
YY:YY:YY - Connection to Syslog succeeded: FAZ1
YY:YY:YY - Connection to Syslog succeeded: FortiSIEM
YY:YY:YY - Aggregator [aggregator-Cloud] changed to Running
YY:YY:YY - Core [core-cloud] changed to Running
YY:YY:YY - Core [core-onprem] changed to Running
What can cause the FortiEDR Manager to restart with the message “Server was restarted”?
Any guidance on where to investigate further would be appreciated.