FortiSIEM Discussions
Yoseph
New Contributor

Fortisiem services down

Hello Everyone,

 

I deployed a FortiSIEM 7.3.0 standalone supervisor and one collector, and they were working properly. However, now the services are frequently down and I can't access the GUI; it requires restarting manually. Even after restarting, they are still too delayed.

additionally, the default Super organization is not found in the list of organizations, and the  collector health status is in Critical (Collector Buffer greater than 50MB).

please, everyone assist on this!

Yoseph Marie
Yoseph Marie
1 Solution
Secusaurus
Contributor III

Hi @Yoseph,

 

At first glance, this sounds like a performance issue. Have a look at the hypervisor of your system and look at the RAM, CPU and drive usages for issues.

 

The collector buffer greater than 50 MB probably is just a result of the supervisor being unavailable, so you can ignore that until you fixed the supervisor's status.

 

In case it's not performance-related: Is there any change (or deployment of new sources, new Agent templates, etc.) you made hours or 1-2 days before the cluster went crazy?

 

Next step would be to look into the crash logs. Since this is a public forum here (and you probably don't like to put your logs here), I would recommend discussing this with the technical support then.

 

Also note, that FSM is actually on 7.3.2 already, which might include a fix, in case this is a bug.

 

Best,

Christian

FCX #003451 | Fortinet Advanced Partner

View solution in original post

FCX #003451 | Fortinet Advanced Partner
2 REPLIES 2
Secusaurus
Contributor III

Hi @Yoseph,

 

At first glance, this sounds like a performance issue. Have a look at the hypervisor of your system and look at the RAM, CPU and drive usages for issues.

 

The collector buffer greater than 50 MB probably is just a result of the supervisor being unavailable, so you can ignore that until you fixed the supervisor's status.

 

In case it's not performance-related: Is there any change (or deployment of new sources, new Agent templates, etc.) you made hours or 1-2 days before the cluster went crazy?

 

Next step would be to look into the crash logs. Since this is a public forum here (and you probably don't like to put your logs here), I would recommend discussing this with the technical support then.

 

Also note, that FSM is actually on 7.3.2 already, which might include a fix, in case this is a bug.

 

Best,

Christian

FCX #003451 | Fortinet Advanced Partner
FCX #003451 | Fortinet Advanced Partner
Yoseph

Hi Christian,

 

Thanks for your quick response regarding the performance It is enough resource, you can check to the bellow screen capture. 

 

Capture.PNG

 
 

 

regards, 

Yoseph

Yoseph Marie
Yoseph Marie