FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
RuiChang
Staff
Staff
Article Id 297038
Description

 

This article provides a  solution for a FortiSIEM Windows Agent that failed to download and install image from the FortiSIEM Supervisor behind Virtual IP.

 

Scope

 

FortiSIEM Windows Agent v4.3.0 and above.

 

Solution

 

In FortiSIEM Windows Agent v4.3.0 and above, it can be upgraded from the feature in FortiSIEM Supervisor. However, it will fail if FortiSIEM Supervisor is configured with Virtual IP, especially for FortiSIEM deployed in Azure, AWS, or other Cloud platforms.

 

In that case, the user will need to verify the database in Windows Agent and notice the table is empty:

Download DB Browser -> Open Database -> Browse to C:\ProgramData\FortiSIEM\Database\AoWinAgt.db

 

RuiChang_0-1706751510611.png

 

For the solution, configure the Virtual Collector IP in Host Template Association in FortiSIEM Supervisor.

Go to FortiSIEM Supervisor GUI -> Admin -> Setup -> Windows Agent -> Host to Template Association.

 

RuiChang_0-1706751563936.png

 

Note:

In the Virtual Collector, insert the Public IP of the Collector.

After the changes above are configured, re-apply the template, and the database in Windows Agent will be updated as well:

 

RuiChang_0-1706751636420.png

 

Note:

IP column will remain empty and will not affect the connection.

After the table is populated with data, the FortiSIEM Supervisor can download and install the image successfully.

 

RuiChang_0-1706751666613.png

 

Related article:

Technical Tip: FortiSIEM Windows Agent change Supervisor IP/FQDN

Contributors