Dear All,
I am using FortiSIEM 5.3.1, i notice some issue when click on Event tab, it suppose to show the details regarding the alert like raw log but i keep getting No data. Any idea why?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Muhammad,
This is under the Incident Tab / select and Incident / Events ... obviously it should be showing data.
Can you do some basic checks from the CLI as root user:
phstatus
--all processes should be up. Make sure your SSH console screen if full screen.
dh -h
-- make sure you have disk space -the /data drive if using the native event database should not be 100% as the system should manage the storage.
top
-- check the load is not too high.. anything <4 should be ok.
How old is the Incident and what is the Rule?
Do you see other event data from that same time period if you run an analytical search?
Thanks
Dan
Dear All,
I am using FortiSIEM 5.3.1, i notice some issue when click on Event tab, it suppose to show the details regarding the alert like raw log but i keep getting No data. Any idea why?
Hi Daniel,
The issue resolve when we reboot collector
-------------------------------------------Hi Muhammad,
This is under the Incident Tab / select and Incident / Events ... obviously it should be showing data.
Can you do some basic checks from the CLI as root user:
phstatus
--all processes should be up. Make sure your SSH console screen if full screen.
dh -h
-- make sure you have disk space -the /data drive if using the native event database should not be 100% as the system should manage the storage.
top
-- check the load is not too high.. anything <4 should be ok.
How old is the Incident and what is the Rule?
Do you see other event data from that same time period if you run an analytical search?
Thanks
Dan
Dear All,
I am using FortiSIEM 5.3.1, i notice some issue when click on Event tab, it suppose to show the details regarding the alert like raw log but i keep getting No data. Any idea why?
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.