FortiSIEM Discussions
lcwoods529
New Contributor

Maintenance mode hanging

Good afternoon,

 We have several devices that go into maintenance mode each Friday until Monday morning because they are on-demand servers. When the period ends, the devices seem to hang in maintenance mode. This only occurs for one organization. Fortinet support has not been of much help. Has anyone seen this issue before and have any solutions to offer. I am NOT our primary admin and can not access the deeper functions but can ask our admin to try certain suggestions

FortiSIEM #6.7.8

6 REPLIES 6
FSM_FTNT
Staff
Staff

are you sure this is for FortiSIEM and not a different Fortinet product?

lcwoods529

Yes, I am sure. 

Secusaurus
Contributor

Hi lcwoods,

 

I suppose, the TAC already asked a couple of these questions, just to dig deeper into that:

  • What is your definition of "hang in maintenance mode"? Are they not triggering incidents? Is there an indication in CMDB or elsewhere showing "maintenance"?
  • What is your exact definition of the maintenance window? (can you share a screenshot?)
  • You state that it is only affecting one organization. Did/can you setup the exactly same maintenance window on another org just to verify? In which view did you create the window (global or inside the org)?
  • Obviously, the TAC will have a look at the AO logs. I don't think, it's good to share them here publicly, but you might want to have a look at these ones (and their errors) by yourself? (I usually start by investigating the AOLogs\appsvr\phoenix.log.gz)

I am pretty sure, TAC should be the one to solve that if it's kind of a bug (perhaps share the ticket id with @FSM_FTNT), but depending on your answers we might uncover a config flaw.

 

Best,

Christian

FCP & FCSS Security Operations | Fortinet Advanced Partner
FCP & FCSS Security Operations | Fortinet Advanced Partner
lcwoods529

Once a device goes into maintenance mode and after the set period has elapsed, it will not receive any metrics. If we attempt a rediscover we receive the error message "device is currently under maintenance" even though the time has elapsed. Fortinet has already reviewed the AO logs. In fact, several admins have. They could  not find anything useful. Their solution is to upgrade to the latest version. For various reasons, that is not a viable solution currently. 

PartBhat
Staff
Staff

Let me try to reproduce it. 

PartBhat

The eng team is unable to reproduce it.  Reproduction attempt steps are as follows.

 

1. Discover a device via SNMP - Success

2. Schedule the device to be in maintenance mode

3. Discover the device while in maintenance mode -> discovery fails

4. Let maintenance mode pass and discover the device -> discovery succeeds

 

Testing was done for both Enterprise and Service Provider versions.

 

Next step would be to provide evidence of failure with detailed steps and screenshots to Support. They can create a mantis bug with this information.

 

 

Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"