FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
premchanderr
Staff & Editor
Staff & Editor
Article Id 304819
Description This article describes how to troubleshoot the 'Connection Refused' error in FortiSIEM GUI > Analytics search 
Scope FortiSIEM v6.x+.
Solution

When running a search in analytics it immediately fails with a 'Connection Refused' error even for small time intervals. 

This would occur if storage is not mounted or storage-related configuration is incorrect. 

 

Here are a few checks to fix this issue:

  1. Validate if correct values are displayed in FortiSIEM GUI -> Admin -> Setup -> Storage.
  2. In the backend check if storage is mounted, enough free space, and permissions are admin.admin:

 

# df -h

# ls -lah /data/eventdb/

 

Note:
'admin:admin' permissions only apply if the 'Event Database' is set on 'Local Event Database' or 'External NFS Database'.

 

  1. The FQDN value of super from the health tab. Run #configFSM.sh to re-run with the same or correct network configuration. Do note this requires a reboot of the system.
  2. Ensure /etc/hosts has the following lines:

 

127.0.0.1 localhost localhost.localdomain
::1 localhost localhost.localdomain
Super-IP   Super-Hostname


It is possible now to perform a search and view events in the FortiSIEM GUI.  If the issue persists, it is then specific to the environment, and a support engineer can help via the support platform