FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
Andy_G
Staff
Staff
Article Id 197916

Description

Summary of Article

If you are not seeing current events on the Super, you can check if there are any cached events files waiting to be uploaded on the Collector.

 

Steps to Implement

1. ssh to the collector as root
2. run “cd /opt/phoenix/cache/parser/events”
3. Run “ls | wc –c” to see how many event files need to be uploaded.
4. run "ls -lt" to see the oldest date for cached events file

 

Additional Information

N/A

 

Version Application

All



 

 

Contributors