FortiSIEM Discussions
adem_netsys
Contributor

No logs from Device

Ekran görüntüsü 2024-08-01 145157.pngEkran görüntüsü 2024-08-01 163058.pngI currently have a rule called "no logs from device" and I expect this rule to be triggered when there is no log from a device, but a device went down and although it did not send logs for a while, the rule was not triggered, is there a custom rule you use for this situation or how can I use it more effectively?

5 REPLIES 5
adem_netsys
Contributor

Does anyone know about this?

bluehawk

Was the device that is down part of the internal system?

adem_netsys

The DC machine is down, but we're getting logs from many machines. So there may be a machine change.

bluehawk

I just checked, and the default rule is working fine, version 7.2.0

adem_netsys

@bluehawk

Although there was no log for about 12 hours, the rule was not triggered, I tried it on a sample machine with the same result. We get logs with windows agent. Do you have any idea?

 

Ekran görüntüsü 2024-08-01 145157.png

Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"