FortiSIEM Discussions
Ricardo_forigua
New Contributor II

Modify rule "No logs from a device"

Hi, I would like to understand the FortiSIEM rule "No logs from a device" which I think is when a device stops sending logs for 10 minutes, I have many alerts and I want to increase the time from 10 minutes to 1 hour, How i can do it?

1 Solution
cdurkin_FTNT
Staff
Staff

2 Options ..

 

1) Globally (for every device)

 

Admin / Device Support / Custom Properties

 

Change the 'EventRecvTimeGapHigh' setting, which defaults to 10 minutes.

 

 

2) Per Individual Device 

 

CMDB / Devices  ..  Edit Device / Device Properties

 

Change the ..

'Event Receive Time Gap High Threshold minutes'. Setting per device.

 

More admin with this method, but you can define a threshold per device.

 

 

 

ie: If a FW has not delivered syslog in the last 5 minutes .. its a issue.

     If a layer 2 switch has not delivered syslog in the last 72 hours .. it might be normal behavior.

View solution in original post

1 REPLY 1
cdurkin_FTNT
Staff
Staff

2 Options ..

 

1) Globally (for every device)

 

Admin / Device Support / Custom Properties

 

Change the 'EventRecvTimeGapHigh' setting, which defaults to 10 minutes.

 

 

2) Per Individual Device 

 

CMDB / Devices  ..  Edit Device / Device Properties

 

Change the ..

'Event Receive Time Gap High Threshold minutes'. Setting per device.

 

More admin with this method, but you can define a threshold per device.

 

 

 

ie: If a FW has not delivered syslog in the last 5 minutes .. its a issue.

     If a layer 2 switch has not delivered syslog in the last 72 hours .. it might be normal behavior.