FortiSIEM Discussions
Furqan_Ahmed
New Contributor

FortiSIEM | Collector critical health status

Hi,

 

We noticed that logs are not uploaded by the collector; check the /opt/phoenix/logs/phoenix.Logs  found in the following logs:

 

2024-10-21T10:10:32.832379+03:00 EuxxCar-Collector phEventPackager[3249]: [PH_EVT_PACKAGER_FILE_UPLOAD_FAILURE]:[eventSeverity]=PHL_WARNING,[procName]=phEventPackager,[fileName]= phEventPKGProcess.cpp,[lineNumber]=1013,[filePath]=/opt/phoenix/cache/parser/events/evt_1729284580_1_355274.dat,[errorNoInt]=403,[destName]=10.7.2.xx3,[phLogDetail]=Failed to upload event file to worker
2024-10-21T10:11:36.901494+03:00 EuxxCar-Collector phEventPackager[3249]: [PH_HTTP_RESPONSE_FAILURE]:[eventSeverity]=PHL_WARNING,[procName]=phEventPackager,[fileName]=phHttpClient.cpp,[lineNumber]=616,[errorNo]=403,[phLogDetail]=HTTP response code failure
2024-10-21T10:11:36.901542+03:00 EuorpCar-Collector phEventPackager[3249]: [PH_EVT_PACKAGER_FILE_UPLOAD_FAILURE]:[eventSeverity]=PHL_WARNING,[procName]=phEventPackager,[fileName]=phEventPKGProcess.cpp,[lineNumber]=1013,[filePath]=/opt/phoenix/cache/parser/events/evt_1729284580_1_355274.dat,[errorNoInt]=403,[destName]=10.7.2.xx3,[phLogDetail]=Failed to upload event file to worker

has context menu

 

Regards,

Syed Furqan Ahmed

 

2 REPLIES 2
Furqan_Ahmed
New Contributor

Can anyone help me on this?

mnovelli
Staff
Staff

Hello @Furqan_Ahmed , it seems you receive an HTTP 403 - Forbidden Not Authorized response from Worker. You should check first of all the services status on Worker (execute phstatus command from CLI) and then investigate /opt/phoenix/logs/phoenix.Logs there. Did you ever change file permissions recently on the worker?

Finally, did you configure the Worker hostname in the Cluster Config GUI configuration?

Regards

Marco

Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"