Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
adem_netsys
Contributor

Create Rule

Hello guys,

 

I want to create a rule in siem. I want it to generate an alarm when a log is not received from a device, when I clone the existing rule, it does not succeed.

3 REPLIES 3
Jean-Philippe_P
Moderator
Moderator

Hello adem_netsys, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

 

Thanks,

Jean-Philippe - Fortinet Community Team
srajeswaran
Staff
Staff

Can you check this post?

go to CMDB / Edit a Device / Properties Tab / Search for Events. You will see "Event Receive Time Gap Low Threshold minutes" and "Event Receive Time Gap High Threshold minutes", change these as needed.

To change it globally Admin / Device Support / Custom Properties, then search as above and edit. Also shows you the default values.


https://www.reddit.com/r/fortinet/comments/dorpfw/trying_to_modify_a_fortisiem_rule_for_delay_of/

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

Labels
Top Kudoed Authors