Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
-- Mathieu Nantel Systems Engineer / Conseiller Technique - Fortinet Montreal, QC
if i want to set alert for device reboot by power distruption then which option should i select
Event handler on the FortiAnalyzer is triggered by logs received from the FortiGates. If all power is lost to the FortiGate, it would not be able to generate a log. It also does not generate a log message upon reboot explaining why it rebooted.
Sounds like you would need to find a way to correlate FortiGate reboots coincided with power fluctuations in your environment. Perhaps if you a UPS solution that is monitoring power availability & it could send syslog to FAZ, it might be possible to use Event Handler somehow. Otherwise, you would need some other monitoring solution. Perhaps involving SNMP.
first of all thanks a lot for quick reply.
i can configure SNMP as well. but in that how can i configure reboot option as there is no such option i can see in fortigate. but if i download MIB file and upload it to SNMP server then will that option be there? if yes what would be name of that option.
i want to configure this now. but i don't have control of SNMP server. so i will send MIB file to SNMP guy. but i need to guide him ro reboot or power disruption which option need to check.
Moreover i don't have fortianalyzer
i have fortimanager . so is it possible to enable Event handler in forti manager. as we have analyzer option also there.
if yes then only for reboot or power distruption which option is there
Sorry, I assumed your question was about FortiAnalyzer because this is a FortiAnalyzer forum.
In general, FortiGates do not record a reason for their last shutdown. Also, although some mid & high range FortiGates have PSU monitors, you still would only be able to poll realtime information on the state of their power supplies.
But you could poll FortiGates for their uptime values
fgSysUpTime OID .1.3.6.1.4.1.12356.101.4.1.20 (from FortiGate MIB)
& correlate that information with polling of some other 3rd party devices like UPS which monitor power conditions.
is it possible to do something on SMTP with MIB file. so that if fortigate goes down i can come to knw in SMTP server ?
That questions is a good one for whatever network monitoring tool you are using. Whether the trigger condition is the output of an SNMP query to the FortiGate or lack of response to a ping probe for a predefined period of X seconds, the alert could presumably trigger an e-mail notification.
The one thing you can do on the FortiAnalyzer (or FortiManager with FortiAnalyzer features enabled) is to define an event handler to be triggered by lack of logging from a FortiGate.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.