FortiSIEM Discussions
Ricardo_forigua
New Contributor II

Modify rule "No logs from a device"

Hi, I would like to understand the FortiSIEM rule "No logs from a device" which I think is when a device stops sending logs for 10 minutes, I have many alerts and I want to increase the time from 10 minutes to 1 hour, How i can do it?

1 Solution
cdurkin_FTNT
Staff
Staff

2 Options ..

 

1) Globally (for every device)

 

Admin / Device Support / Custom Properties

 

Change the 'EventRecvTimeGapHigh' setting, which defaults to 10 minutes.

 

 

2) Per Individual Device 

 

CMDB / Devices  ..  Edit Device / Device Properties

 

Change the ..

'Event Receive Time Gap High Threshold minutes'. Setting per device.

 

More admin with this method, but you can define a threshold per device.

 

 

 

ie: If a FW has not delivered syslog in the last 5 minutes .. its a issue.

     If a layer 2 switch has not delivered syslog in the last 72 hours .. it might be normal behavior.

View solution in original post

1 REPLY 1
cdurkin_FTNT
Staff
Staff

2 Options ..

 

1) Globally (for every device)

 

Admin / Device Support / Custom Properties

 

Change the 'EventRecvTimeGapHigh' setting, which defaults to 10 minutes.

 

 

2) Per Individual Device 

 

CMDB / Devices  ..  Edit Device / Device Properties

 

Change the ..

'Event Receive Time Gap High Threshold minutes'. Setting per device.

 

More admin with this method, but you can define a threshold per device.

 

 

 

ie: If a FW has not delivered syslog in the last 5 minutes .. its a issue.

     If a layer 2 switch has not delivered syslog in the last 72 hours .. it might be normal behavior.

Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"