Hi, I would like to understand the FortiSIEM rule "No logs from a device" which I think is when a device stops sending logs for 10 minutes, I have many alerts and I want to increase the time from 10 minutes to 1 hour, How i can do it?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
2 Options ..
1) Globally (for every device)
Admin / Device Support / Custom Properties
Change the 'EventRecvTimeGapHigh' setting, which defaults to 10 minutes.
2) Per Individual Device
CMDB / Devices .. Edit Device / Device Properties
Change the ..
'Event Receive Time Gap High Threshold minutes'. Setting per device.
More admin with this method, but you can define a threshold per device.
ie: If a FW has not delivered syslog in the last 5 minutes .. its a issue.
If a layer 2 switch has not delivered syslog in the last 72 hours .. it might be normal behavior.
2 Options ..
1) Globally (for every device)
Admin / Device Support / Custom Properties
Change the 'EventRecvTimeGapHigh' setting, which defaults to 10 minutes.
2) Per Individual Device
CMDB / Devices .. Edit Device / Device Properties
Change the ..
'Event Receive Time Gap High Threshold minutes'. Setting per device.
More admin with this method, but you can define a threshold per device.
ie: If a FW has not delivered syslog in the last 5 minutes .. its a issue.
If a layer 2 switch has not delivered syslog in the last 72 hours .. it might be normal behavior.
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.