FortiSIEM Discussions
cheerio
New Contributor

How Can I Detect Devices Not Logging/Reporting

What is the best course of action to detect devices not properly logging?

Example: If a new device is added to an environment and sends an initial log, but another log isn't sent another 24 hours, will an alert generate?

 

Also, for devices that are currently stopped logging, what would be the best course of action to capture that info?

1 REPLY 1
premchanderr
Staff
Staff

Hi @cheerio ,

 

You can use CMDB > CMDB Report "Device Monitoring Errors" - This reports devices whose performance / availability monitoring status is Warning or Critical . 

 

Additionally look out for CMDB Reports > Device Event Collection Status , Device Event Collection Errors etc

Regards,
Prem Chander R