FortiSIEM Discussions
adem_netsys
Contributor

Create Rule Issue

Hi guys,

 

I use the default "no logs from device" rule to generate an alarm when there is no log from all my products, but I want my two dc machines to come with a separate rule, not in this rule, so I added these two machines as an exception to the existing rule and cloned this rule and wrote it separately for only two machines, but it gave a sync error and did not work.

1 REPLY 1
premchanderr
Staff
Staff

Hi @adem_netsys ,

Rule sync error would be due to rule badly written and any fields invalid. You would need to review the rule and better to open support request since its specific to your environment. 


This documentation would be useful:
https://community.fortinet.com/t5/FortiSIEM/Technical-Tip-How-to-troubleshoot-rules/ta-p/303822

Regards,
Prem Chander R
Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"