Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How Can I Detect Devices Not Logging/Reporting
What is the best course of action to detect devices not properly logging?
Example: If a new device is added to an environment and sends an initial log, but another log isn't sent another 24 hours, will an alert generate?
Also, for devices that are currently stopped logging, what would be the best course of action to capture that info?
Labels:
- Labels:
-
FortiSIEM
-
FortiSiem 7.1
1 REPLY 1
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @cheerio ,
You can use CMDB > CMDB Report "Device Monitoring Errors" - This reports devices whose performance / availability monitoring status is Warning or Critical .
Additionally look out for CMDB Reports > Device Event Collection Status , Device Event Collection Errors etc
Regards,
Prem Chander R
Prem Chander R
