Hi,
I am using 7.1.6 version SIEM and I installed the latest version agent in a new environment and configured it to go only to the Collector, in the latest versions, I think you can also remove the supervisor with super override via the agent exe file. After this process, I saw the agent as disconnect on SIEM Gui and when I examined it in Firewall, I noticed that it was trying to access both super and collector. I am using a multi-tenant structure, I can see the agent by selecting All in the organisation, but it is not included when I select collector. Does anyone have any ideas for this?
The Super Override option is only for a niche specific use case, where multiple supervisors are used, is this your case?
Have you configured your collector as a proxy?
https://docs.fortinet.com/document/fortisiem/7.1.7/windows-agent-7-1-x-installation-guide/547950/for...
There is only 1 supervisor in the environment, I have already applied the document you mentioned below, I reinstalled it by removing the supers override, but it is trying to reach the supervisor ip again.
Can you share (obfuscate any sensitive information) screenshots of your Agent configuration?
Running 7.1.7 version of the agent?
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
User | Count |
---|---|
72 | |
25 | |
15 | |
10 | |
10 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.