Hi guys,
I use the default "no logs from device" rule to generate an alarm when there is no log from all my products, but I want my two dc machines to come with a separate rule, not in this rule, so I added these two machines as an exception to the existing rule and cloned this rule and wrote it separately for only two machines, but it gave a sync error and did not work.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @adem_netsys ,
Rule sync error would be due to rule badly written and any fields invalid. You would need to review the rule and better to open support request since its specific to your environment.
This documentation would be useful:
https://community.fortinet.com/t5/FortiSIEM/Technical-Tip-How-to-troubleshoot-rules/ta-p/303822
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.