Skip to main content
sean_gurdon
New Member
July 16, 2020
Question

Fortisiem Status Definitions

  • July 16, 2020
  • 1 reply
  • 3660 views

Hello, so I was wondering what the different status' mean. 

I know that the status' are Active, Cleared, Cleared Manually and Cleared by System. 

I think that the other three are self explanatory, but can someone give me some incite as to what the Active Status means?  

    1 reply

    FSM_FTNT
    Staff
    Staff
    July 24, 2020

    Hi Sean,

     

    Active = Incident is active

    "Auto" Cleared = Automatically Cleared by a Rule with a clear condition set.

    Cleared Manually = User Cleared.

    Cleared by System = Performance and Availability related incidents are cleared every 24 hours.

     

    You can change the time that the Incidents are cleared under as well as what incidents are cleared

    /opt/phoenix/config/phoenix_config.txt

     

    auto_clear_security_incidents=0 #0 not system clear security incident; 1 system clear security incident

    deprecated_time=86400 #1 day

     

    Thanks

     

    Dan

     

    adem_netsys
    Explorer III
    August 23, 2023

    Hi guys,

     

    we don't want to receive this warning mail. can we do that?