FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
lucianag22
Staff
Staff
Article Id 337988
Description

This article explains why a new Collector goes into Critical Status due to it is not able to send events to the Supervisor or Worker node, Last File Received is in Critical status.

The following errors are continuously generated in the collector phoenix log tail -f /opt/phoenix/log/phoenix.log.

 

2024-08-30T16:31:36.031019-05:00 collector713 phEventPackager[3512]: [PH_EVT_PACKAGER_FILE_UPLOAD_FAILURE]:[eventSeverity]=PHL_WARNING,[procName]=phEventPackager,[fileName]=phEventPKGProcess.cpp,[lineNumber]=1008,[filePath]=/opt/phoenix/cache/parser/events/evt_1725051969_3_0.dat,[errorNoInt]=405,[destName]=10.0.1.39,[phLogDetail]=Failed to upload event file to worker

2024-08-30T16:32:37.052748-05:00 collector713 phEventPackager[3512]: [PH_HTTP_RESPONSE_FAILURE]:[eventSeverity]=PHL_WARNING,[procName]=phEventPackager,[fileName]=phHttpClient.cpp,[lineNumber]=609,[errorNo]=405,[phLogDetail]=HTTP response code failure

2024-08-30T16:32:37.052762-05:00 collector713 phEventPackager[3512]: [PH_EVT_PACKAGER_FILE_UPLOAD_FAILURE]:[eventSeverity]=PHL_WARNING,[procName]=phEventPackager,[fileName]=phEventPKGProcess.cpp,[lineNumber]=1008,[filePath]=/opt/phoenix/cache/parser/events/evt_1725051969_3_0.dat,[errorNoInt]=405,[destName]=10.0.1.39,[phLogDetail]=Failed to upload event file to worker

Scope FortiSIEM Nodes.
Solution
  1. Go to the FortiSIEM GUI https://<ip_of_supervisor>.

  2. Go to ADMIN -> Settings -> System -> Cluster Config and check the IP address under Event Upload Workers.
     

     

    ClusterSettings.PNG

     

  3. If there is a Worker(s) node in the FortiSiem Cluster, the Worker(s) IP address should be used, real IP and/or VIP, if not having a Worker node the Supervisor IP addresses should be used. Note: Collector IP addresses should not be set in this field.

  4. Additionally, check if an Event Worker is defined in the Collector Settings under Admin -> -Setup -> Collector -> Event Collector Definition. Collector IP addresses should not be set in this field. For Service Provider deployment, go to Admin -> Setup -> Organizations -> Collector Settings.

  5. After setting the proper IP address under Event Upload Workers, error logs should no longer appear on the collector.

 

tail -f /opt/phoenix/log/phoenix.log

Related documents:

Troubleshooting Tip: Collector cannot upload SVN files 

Cluster Config