I Was implemented FortiSIEM super with collector but now it seems to me in the health collector warning then become critical found all the services down then restart all the services works fine but the (phAgentManager) restart then down and restart then down. I want to solve this and why or what cause this down
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
This does not seem like normal behavior and therefore you could raise a TAC case to investigate. However, I have seen a similar issue with a collector on version 7.1.X. Upgrading to 7.2 fixed the issue for me.
Best regards
Hi @Richie_C
can you provide me how to upgrade from 7.1.1 to 7.2 from the gui and i had a question when upgrade the supervisor should i shut down the collector or not
Created on 10-20-2024 11:53 AM Edited on 10-21-2024 01:24 AM
The instructions for upgrading the collector from the supervisor GUI are as follows:
In addition, I would always recommend checking the release notes and upgrade guide before doing an upgrade:
https://docs.fortinet.com/document/fortisiem/7.2.3/release-notes/515687/whats-new-in-7-2-3
https://docs.fortinet.com/document/fortisiem/7.2.3/upgrade-guide/505373/upgrading-to-fortisiem-7-2-x
The collector must be up for this to work.
Make sure you take a snapshot before the upgrade, so that you can restore in case of any issues.
I hope that helps!
hi @Richie_C
I performed the upgrade and successfully upgraded the supervisor and the collector the restarting loop of phAgentManager resolved well after the upgrade but i found in the phstatus the parser start into the restart loop checked everything but i can't to reach which cause this restart or the issue where i had already open a TAC to investigate after the upgrade they closed the ticket they approved the upgrade was success without any investigation
It sounds like you might have to create a new ticket. However, is this a problem on the supervisor, the collector or both?
Do you have any custom parsers? If so, maybe you could try disabling the custom parsers and see if it fixes the issue.
Regards
Hi @Richie_C
this problem on the collector only.
If i had a custom parsers yes but the QNAP will not parsing because from the previous Ticket which opened the TAC change the qlogd to qilogd in the xml parser.
Hi @Saleh_Mostafa - you could try to disable the custom parser and see if it resolves the issue. Then you will know if it is the root cause of your problem.
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.