FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
FortiKoala
Staff
Staff
Article Id 190872
Description

How Do I Safely Reboot the Windows Server(s)


Scope

Installation and Administration


Solution

Valid as of ZoneFox version 4.1

Preparing for Reboot

In order to safely reboot the Windows Server(s) you must ensure that there is no data throughput. This can be done by first switching off the Collector Server (CS) on the Windows server(s). The CS can be managed through Internet Information Service (IIS) Manager on the windows server. Select the Collector Server site and under Manage Website click Stop.  



With the CS stopped the agents will no longer send events to the server. Instead they will cache events locally until the CS is back online.


Next ensure that the MSMQ queue for the business lay is empty. Go to Computer Management > Services and Applications > Message Queuing > Private Queues. You should be able to see a queue called cs_to_bl and the number of messages



Recovering After Reboot

Before allowing the data throughput again you need to ensure that all components are ready.


Next ensure that the business layer is running. In Task Manager go to the Services tab and ensure that ZF.BL and ZF.BL.Nesper are running. If not first right click on the service ZF.BL.Nesper and click Start. Wait until the status is running. Next do the same for the service ZF.BL. Ensure that it is running. The order in which you do this is important. If you failed to follow these instruction stop both services again and start them in the correct order.

If either fail to start please examine the logs and contact ZoneFox support.



Next start the collector server again. Go back to Internet Information Service (IIS) Manager, select the Collector Server site and under Manage Website and click Start. To ensure that the CS is running correctly go the url https://<windows_server>:<port(8080_by_default)>. It will return a json output like this:



You can also check the system status page in your ZoneFox console. Go to Admin - System and expand the different graphs for different components to check their throughput.















Contributors