Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sean_gurdon
New Contributor

Fortisiem Status Definitions

Hello, so I was wondering what the different status' mean. 

I know that the status' are Active, Cleared, Cleared Manually and Cleared by System. 

I think that the other three are self explanatory, but can someone give me some incite as to what the Active Status means?  

2 REPLIES 2
FSM_FTNT
Staff
Staff

Hi Sean,

 

Active = Incident is active

"Auto" Cleared = Automatically Cleared by a Rule with a clear condition set.

Cleared Manually = User Cleared.

Cleared by System = Performance and Availability related incidents are cleared every 24 hours.

 

You can change the time that the Incidents are cleared under as well as what incidents are cleared

/opt/phoenix/config/phoenix_config.txt

 

auto_clear_security_incidents=0 #0 not system clear security incident; 1 system clear security incident

deprecated_time=86400 #1 day

 

Thanks

 

Dan

 

adem_netsys

Hi guys,

 

we don't want to receive this warning mail. can we do that?

Labels
Top Kudoed Authors