FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
gagandeeps
Staff
Staff
Article Id 366777
Description This article describes the optimization of the FSSO agent when the collector agent shows an unprocessed logon event in the log file.
Scope FSSO collector agent installed on Windows server.
Solution

Error: 'Multiple unprocessed logon events in the log file from the collector agent.'

 

12/02/2024 11:41:12 [ 6040] unprocessed logon event:24000
12/02/2024 11:41:15 [ 4776] unprocessed logon event:23000

 

'Unprocessed logon events' notifications show up repeatedly in collector agent servers, particularly when DCs or CA servers go down and up. FortiGate lacks certain logon events that are absent from the Collector Agent.

 

As a result, numerous people experience issues accessing the internet.

 

Solution:

Optimization of the collector agent is as follows:

  1. Change the Max worker thread to 576 on logic- Max Worker Threads = 512 + ((Logical CPUs − 4) × 16).
  2. Set log level to Debug and log size to 100 MB.
  3. Set Cache user group results to 60