Hi,
Forticliente EMS 7.0.7 license ZTNA. Since yesterday I have this message in the dashboard but if I click on it no host appears.
Another question: I have had ForticlientEMS for months but in the "FortiGuard Outbreak Detection" section I always see only these four signatures:
Solved! Go to Solution.
Hi FortiMax_it,
The first issue is likely a bug
781654 | EMS does not remove dashboard outbreak alerts when endpoint disconnects. |
https://docs.fortinet.com/document/forticlient/7.0.7/ems-release-notes/310815/known-issues
To elaborate, the root cause of this bug is that the dashboard widget is not filtering endpoints that historically have had the tag, meaning it is showing current and historical in the widget. However, when you drill down it only shows the endpoints that currently have the tag.
An endpoint can lose that tag if the endpoint is disconnected from EMS, or if the endpoint is no longer infected.
The fix for this bug is included in 7.0.8
-------------------------------------------------
For the second issue, it appears your Outbreak Alerts Signatures are not updating. As you can see here, the version is up to 1.00073.
It is possible you are encountering bug 813928 (found in the same release notes linked above). You may try the listed workaround of restarting fcems service on the server hosting EMS.
If that fails, I would troubleshoot why it is not receiving updates. Try increasing your logging level to debug and attempting the update. Please open a ticket with support if you require further guidance or assistance.
Hello FortiMax_it!
Thank you for using the Community Forum.
I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Kindest regards,
Hi FortiMax_it,
The first issue is likely a bug
781654 | EMS does not remove dashboard outbreak alerts when endpoint disconnects. |
https://docs.fortinet.com/document/forticlient/7.0.7/ems-release-notes/310815/known-issues
To elaborate, the root cause of this bug is that the dashboard widget is not filtering endpoints that historically have had the tag, meaning it is showing current and historical in the widget. However, when you drill down it only shows the endpoints that currently have the tag.
An endpoint can lose that tag if the endpoint is disconnected from EMS, or if the endpoint is no longer infected.
The fix for this bug is included in 7.0.8
-------------------------------------------------
For the second issue, it appears your Outbreak Alerts Signatures are not updating. As you can see here, the version is up to 1.00073.
It is possible you are encountering bug 813928 (found in the same release notes linked above). You may try the listed workaround of restarting fcems service on the server hosting EMS.
If that fails, I would troubleshoot why it is not receiving updates. Try increasing your logging level to debug and attempting the update. Please open a ticket with support if you require further guidance or assistance.
Hi, I had tried to restart the fcems service and the server but nothing changed. I think I solved it by removing the SSL for the Fortiguard because after putting port 80, not immediately but after several hours, the new Outbreak Detection were populated.
For bug 781654 ok, thank you, I'll wait. Is there an ETA for version 7.0.8?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.