FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
idabouzi
Staff
Staff
Article Id 303122
Description This article describes how to apply content updates manually through the CLI, as an alternative to performing an update automatically through the GUI.
Scope FortiSIEM.
Solution
  1. Check the latest available update version in the output file /tmp/contentInfo. SSH to the Superviser:

su admin

content-update.sh check <running_siem_version> <running_content_update_version> -o /tmp/contentInfo

Example:
      

su admin
content-update.sh check 7.1.3 600 -o /tmp/contentInfo

   => Output: 'latest': '605'

 

  1. Remove old content update files if there are any:

rm -rvf /opt/phoenix/ContentUpgrade/*

 

  1. Install the latest content update:

su - admin
$ content-update.sh apply <running_siem_version> <running_content_update_version> --pkg /opt/phoenix/ContentUpgrade/fullContentPkg.tgz

Example: Updating from the current running content updates version 600:

content-update.sh apply 7.1.3 600 --pkg /opt/phoenix/ContentUpgrade/fullContentPkg.tgz

 

  1. Update the CMDB with the content version installed on the system:

psql -U phoenix -d phoenixdb -c "update ph_sys_conf set value='<lastest_content_update_version>' where property = 'Content_Update_Version';"

 

Update 1 should be seen as the output.

Example

psql -U phoenix -d phoenixdb -c "update ph_sys_conf set value='605' where property = 'Content_Update_Version';" 

             

  1. Restart the application server:

 

rm -rf /opt/phoenix/cache/content/
rm -rf /opt/glassfish/domains/domain1/generated/
rm -rf /opt/glassfish/domains/domain1/osgi-cache/
killall -9 java

 

  1. Once the GUI is available again, navigate to ADMIN -> Content Update and select the 'Check Now' button, which should show a 'No available updates' message.