Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FortiMax_it
Contributor

ForticlientEMS: FortiGuard Outbreak Detection

Hi,

Forticliente EMS 7.0.7 license ZTNA. Since yesterday I have this message in the dashboard but if I click on it no host appears.

Screenshot_17.png
Screenshot_18.png

Another question: I have had ForticlientEMS for months but in the "FortiGuard Outbreak Detection" section I always see only these four signatures:

Screenshot_22.pngSignaturesSignatures

LOG: 2022-10-21 07:37:13 - Info -Update Service - No updates available -1 time since 2022-10-21 07:37:13
1 Solution
ck_FTNT
Staff
Staff

Hi FortiMax_it,

 

The first issue is likely a bug 

781654 EMS does not remove dashboard outbreak alerts when endpoint disconnects.

https://docs.fortinet.com/document/forticlient/7.0.7/ems-release-notes/310815/known-issues

 

To elaborate, the root cause of this bug is that the dashboard widget is not filtering endpoints that historically have had the tag, meaning it is showing current and historical in the widget. However, when you drill down it only shows the endpoints that currently have the tag.

 

An endpoint can lose that tag if the endpoint is disconnected from EMS, or if the endpoint is no longer infected.

 

The fix for this bug is included in 7.0.8

-------------------------------------------------

For the second issue, it appears your Outbreak Alerts Signatures are not updating. As you can see here, the version is up to 1.00073.

 

It is possible you are encountering bug 813928 (found in the same release notes linked above). You may try the listed workaround of restarting fcems service on the server hosting EMS.

 

If that fails, I would troubleshoot why it is not receiving updates. Try increasing your logging level to debug and attempting the update. Please open a ticket with support if you require further guidance or assistance.

View solution in original post

3 REPLIES 3
Jean-Philippe_P
Moderator
Moderator

Hello FortiMax_it!

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Kindest regards,

Jean-Philippe - Fortinet Community Team
ck_FTNT
Staff
Staff

Hi FortiMax_it,

 

The first issue is likely a bug 

781654 EMS does not remove dashboard outbreak alerts when endpoint disconnects.

https://docs.fortinet.com/document/forticlient/7.0.7/ems-release-notes/310815/known-issues

 

To elaborate, the root cause of this bug is that the dashboard widget is not filtering endpoints that historically have had the tag, meaning it is showing current and historical in the widget. However, when you drill down it only shows the endpoints that currently have the tag.

 

An endpoint can lose that tag if the endpoint is disconnected from EMS, or if the endpoint is no longer infected.

 

The fix for this bug is included in 7.0.8

-------------------------------------------------

For the second issue, it appears your Outbreak Alerts Signatures are not updating. As you can see here, the version is up to 1.00073.

 

It is possible you are encountering bug 813928 (found in the same release notes linked above). You may try the listed workaround of restarting fcems service on the server hosting EMS.

 

If that fails, I would troubleshoot why it is not receiving updates. Try increasing your logging level to debug and attempting the update. Please open a ticket with support if you require further guidance or assistance.

FortiMax_it

Hi, I had tried to restart the fcems service and the server but nothing changed. I think I solved it by removing the SSL for the Fortiguard because after putting port 80, not immediately but after several hours, the new Outbreak Detection were populated.

For bug 781654 ok, thank you, I'll wait. Is there an ETA for version 7.0.8?

Labels
Top Kudoed Authors