FortiSIEM Discussions
Furqan_Ahmed
New Contributor

FortiSIEM | Collector critical health status

Hi,

 

We noticed that logs are not uploaded by the collector; check the /opt/phoenix/logs/phoenix.Logs  found in the following logs:

 

2024-10-21T10:10:32.832379+03:00 EuxxCar-Collector phEventPackager[3249]: [PH_EVT_PACKAGER_FILE_UPLOAD_FAILURE]:[eventSeverity]=PHL_WARNING,[procName]=phEventPackager,[fileName]= phEventPKGProcess.cpp,[lineNumber]=1013,[filePath]=/opt/phoenix/cache/parser/events/evt_1729284580_1_355274.dat,[errorNoInt]=403,[destName]=10.7.2.xx3,[phLogDetail]=Failed to upload event file to worker
2024-10-21T10:11:36.901494+03:00 EuxxCar-Collector phEventPackager[3249]: [PH_HTTP_RESPONSE_FAILURE]:[eventSeverity]=PHL_WARNING,[procName]=phEventPackager,[fileName]=phHttpClient.cpp,[lineNumber]=616,[errorNo]=403,[phLogDetail]=HTTP response code failure
2024-10-21T10:11:36.901542+03:00 EuorpCar-Collector phEventPackager[3249]: [PH_EVT_PACKAGER_FILE_UPLOAD_FAILURE]:[eventSeverity]=PHL_WARNING,[procName]=phEventPackager,[fileName]=phEventPKGProcess.cpp,[lineNumber]=1013,[filePath]=/opt/phoenix/cache/parser/events/evt_1729284580_1_355274.dat,[errorNoInt]=403,[destName]=10.7.2.xx3,[phLogDetail]=Failed to upload event file to worker

has context menu

 

Regards,

Syed Furqan Ahmed

 

2 REPLIES 2
Furqan_Ahmed
New Contributor

Can anyone help me on this?

mnovelli
Staff
Staff

Hello @Furqan_Ahmed , it seems you receive an HTTP 403 - Forbidden Not Authorized response from Worker. You should check first of all the services status on Worker (execute phstatus command from CLI) and then investigate /opt/phoenix/logs/phoenix.Logs there. Did you ever change file permissions recently on the worker?

Finally, did you configure the Worker hostname in the Cluster Config GUI configuration?

Regards

Marco