Category Archives: FortiSIEM

FortiSIEM Whats New In 4.4.3

What’s new in Release 4.4.3

This release contains the following bug fixes and enhancements.

Bug

ID

Severity Component Description
13806 Major Performance

Monitoring

Server restart detection based on up time does not always work correctly in one case – if the server was in maintenance mode and this is the first time after maintenance and there was a server restart during maintenance.
14527 Major App Server Newly created Blocked IP and Domain groups can not be always downloaded correctly by the back end modules because the name in malware value group is incorrectly replaced by natural Id
14565 Major App Server Adding an Incident related report to Business Service Dashboard can cause the Dashboard to not show results
14650 Major App Server Upgrade from 4.4.1 to 4.4.2 may lead to duplicate Windows Servers in CMDB. In 4.4.2, hardware serial number is added to Windows server from Bios discovery via WMI. If a windows server existed in CMDB before 4.4.2, rediscovery in 4.4.2 would create a new windows server in CMDB with hardware serial number. The two windows servers one without hardware serial number and one with, would nor be merged. Workaround in 4.4.2 would be to delete the Windows server without hardware serial number.
14652 Major App Server Some rules created before 4.4.2 does not work after upgrade. The rule caching optimization introduced in 4.4.2 has a bug which ignores some rules with empty created date values. Workaround in 4.4.2 would be to disable and then re-enable the rule.
14705 Major App Server User edits to interface speeds are overwritten by Discovery. This bug was introduced when we added two fields – sent speed and receive speed to replace the single interface speed
14726 Major App Server Custom properties (such as global CPU utilization thresholds, per-device CPU utilization thresholds) are lost after upgrade
14201 Normal Parser Drop IPv6 net flow records if IPv6 and IPv4 records are mixed in received Netflow records – since we do not currently handle IPv6 records and they take up lots of storage space
14476 Normal System Disable rate limit on rsyslog – this would ensure that all internal logs would be accurately received by the system
14477 Normal Performance

Monitoring

Performance Monitor module crashes sometime due to memory corruption
14528 Normal App Server Blocked Domain and IP fields can not be downloaded if a field contains double quote in a field
14666 Normal Performance

Monitoring

The character \” in raw message causes custom WMI based performance monitor to have errors
14690 Normal Data The “A system User Created” rule in incorrectly categorized as a Availability rule
14700 Normal Data

Manager

Do not abort when DataManager module fails to create directories in NFS. Create a log

PH_UNABLE_CREATE_DIR_1. The rule “System Critical: DataManager event store failed” would trigger.

14724 Normal Report

Worker

In the Summary dashboard, the display of Availability Status column depends on the display of Ping Packet Loss column. So if the Ping Packet Loss column is removed, then the Availability Status column is also not displayed.
14395 Enhancement System Optimize the number of value group requests from back end modules to Application Server by caching – this would reduce the load on the Application Server specially when there are lots of value groups resulting from large number of organizations, business services or large number pf CMDB Objects used in rules and reports
14567 Enhancement System Beaconing – report Unknown Event Types as aggregates – not the raw events themselves
14584 Enhancement Discovery,

Performance Monitoring

Add discovery and Performance Monitoring for Cisco FirePower IPS module
14688 Enhancement Discovery,

Performance Monitoring

Add discovery and Performance Monitoring for Dell NSeries 4xxx switches
14691 Enhancement Discovery,

Performance

Monitoring

Add discovery and Performance Monitoring for H3C Comware
14684 Enhancement App Server Bound the number of API downloaded Threat feed entries in the AccelOps CMDB – by default we never keep more than 100K active entries per threat feed group in AccelOps CMDB by default. This number can be increased or decreased by the user at their own risk. Since there is not guarantee on the quality and number of items in the external threat database, a sudden surge of downloaded entries can have detrimental effect on AccelOps system performance.
14720 Enhancement Data Parse a new format of Bit9 syslog
14651 Enhancement Data Parse Dell NSeries syslog
14671 Enhancement Data Squid Parser needs enhancements for RHEL 7 and squid 3.3
14694 Enhancement Data AccelOps Windows Agent generated DHCP logs must also populated Identity location table

 

14699 Enhancement Data Add 11 more Windows Security event types

 

 


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

FortiSIEM What’s New in 4.4.5

What’s new in Release 4.4.5

This release contains the following bug fixes and enhancements. It fixes several issues that were newly introduced in 4.4.3.

Bug

ID

Severity Component Description
15111 Major GUI (AO-SP) Rule exceptions created under an organization are not saved
15160 Major GUI Malware hash update via API does not work
15121 Major Parser Netflow events may be dropped because templates not maintained correctly. This was newly introduced in 4.4.3.
15075 Major System Clear cache operation in phMonitor module could keep global cache lock and blocking global cache access. This was newly introduced in 4.4.3.
15099 Major System Lack of mutex can cause a deadlock in phMonitor causing the system to not function correctly. This was newly introduced in 4.4.3.
15074 Major Query A race condition may cause Query Worker to enter a deadlock stage preventing queries from progressing.
15104 Major Performance

Monitor

Class based QoS data not generated even though the job is added.
15101 Minor Application

Server

Too many sockets opened while running a scheduled Report bundle may cause queries to fail.
15102 Minor Application

Server

(AO-SP) Rulemaster module may not pick up user changes on Rule exception for a specific organization
14834 Normal System Partial archives directory can prevent Event DB purging leading to Event DB becoming full.
15112 Normal GUI (AO-SP) Rule Exception notes not saved in per Org level
15100 Normal Application

Server

Improper exception thrown by Application Server on an invalid query may block other queries from progressing.
15162 Enhancement System Disable AccelOps internal Apache logging.
15163 Enhancement System Download of CMDB Objects containing large IP values (e.g. Blocked IP object containing malware data) needs to be optimized.
15166 Enhancement Data Handle new version of Cisco FirePower logs.
15176 Enhancement GUI Identity and location may take a long time to load if the default time window is 1 day – set the default to 1 hour.

 

 


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

FortiSIEM What’s New in 4.5.1

What’s New in Release 4.5.1

NEW RELEASE 4.5 UPGRADE REQUIREMENT

Starting 4.5, Supervisor requires 24GB RAM. The increase from 16GB RAM in prior releases is needed for the data collection robustness and visibility feature.  Supervisor node is now caching device monitoring status for faster performance by avoiding database I/O. Without the additional RAM, Supervisor node will not operate properly.

 

This release adds features and functionality in several areas.

Platform Features

Data collection robustness and visibility

Export events to other Big Data systems via Kafka

CMDB Outbound Integration for ConnectWise Dashboard slideshow

Performance and Availability Monitoring

Maintenance calendar for Synthetic Transaction Monitor jobs

Real time performance probing

SLA calculation for SNMP and WMI Ping

Trace route monitoring

Log Management and Security Monitoring

Multi-tenant reporting device handling

Windows Agent Enhancements

Device Support

New Support

Enhanced Support

Significant Enhancements

DataManager and ReportWorker module robustness

Additional metrics on trend charts

Simplify Cloud and Collector health GUI

Ability to manually add hosts to Application Groups

Set important process and critical interface definitions directly from CMDB

Dashboard charting enhancements

Accounting for internal and performance monitoring events

Ability to change event database purge/archive thresholds

Ability to set remote directory renaming action during archive Registration APIs

Bug Fixes / Enhancements

Current Open Bugs/Enhancements

 

Platform Features

Data collection robustness and visibility

This release enhances the reliability and visibility of AccelOps data collection in the following ways.

Detailed visibility on when data was last collected: (a) data from performance monitoring jobs on a per device, per job basis and (b) data pushed from external devices on a per device per protocol basis. Last collection times are visible by simply visiting CMDB > Device > Monitor tab. The times are updated frequently (every 2 minutes).

A versioning scheme is introduced to make sure that the Application Server and the data collection agents (Java agents and Performance Monitor modules in Collectors, Workers) are always in sync. This ensures that when user changes (either manual or from discovery) are always reflected in data collection. If there is a version discrepancy, means that data collection agents are not working on the most up to date version, an alert is created based on a system rule.

System rules are provided for the following error scenarios: User can decide to restart a module or the entire application via a notification policy/remediation scripts.

  1. all jobs on a data collection agent are delayed
  2. a particular job on a data collection agent are delayed
  3. a version discrepancy is detected – a data collection agent (Collector, Worker) has not picked up the correct monitoring version within a certain amount of time

Details on how data collection times and status is reported in CMDB are here.

Export events to other Big Data systems via Kafka

AccelOps collects a wide variety of logs and performance metrics and uses the data for its own analysis. This release enables users to export the logs in a parsed format to any external system via Kafka, a highly scalable distributed message bus (see Apache Kafka). AccelOps has developed a connector that publishes to the Kafka message bus. This feature can be used to populate a Big Data system with rich AccelOps data.

Details on configuring AccelOps for Kafka export is discussed here

CMDB Outbound Integration for ConnectWise

ConnectWise is an important help desk / ticketing system specially for service providers. AccelOps already has two-way integration with

ConnectWise ticketing – a ticket can be created in ConnectWise and state updates in ConnectWise is reflected in AccelOps. This release extends the integration to cover CMDB. When AccelOps discovers a device, ConnectWise CMDB can be populated, either automatically or on demand. When AccelOps discovers changes, the change can be synced to ConnectWise. A framework is provided to convert device attributes like Organizations, host names, device types to ConnectWise specific fields and fields.

Details on configuring AccelOps for ConnectWise outbound CMDB integration is discussed here. AccelOps provides a special content mapping feature where any AccelOps CMDB attribute and values can be converted into a corresponding ConnectWise CMDB attribute and values (see Step 11).

Dashboard slideshow

Users are now able to select a set of dashboards and display them in a slideshow mode on big monitors to cover the entire display. This is useful for Network and Security Operation Centers.

Details on creating dashboard slideshow is discussed here.

Performance and Availability Monitoring

Maintenance calendar for Synthetic Transaction Monitor jobs

This release allows the ability to add Synthetic Transaction Monitor (STM) jobs to a maintenance calendar. While a STM job is under maintenance, the job is not executed and system rule does not trigger if the job fails.

Details on how to create maintenance calendars for STM jobs is detailed here.

Real time performance probing

Often for checking the health of a device or an application, it is necessary to probe the device and check its current performance metrics. Until now, the option in AccelOps would be to query the system for performance monitoring events – this does not quite serve the purpose since the polling intervals are too large (3 minutes of so for most jobs) – so you would not get results for next 3 minutes. This release allows users to probe the device at a much faster pace (e.g. few seconds apart) and see the metrics in a real time scrolling fashion on the GUI. These metrics are polled in addition to the regular scheduled performance polls – they are neither stored nor do they trigger any rules or are part of any report. Currently, only a subset of important system performance metrics are supported for real time performance probes, e.g. system CPU, memory, disk, interface and process utilization.

Details on how to probe devices for real time performance metrics is discussed here.

SLA calculation for SNMP and WMI Ping

Until now, we calculated Min/Max/Average Round Trip Time, downtime and SLA for ICMP Ping only. This notion is extended for two other critical performance monitoring protocols – SNMP and WMI.The events PH_DEV_MON_SNMP_PING_STAT and PH_DEV_MON_WMI_PING_STAT now contain the following additional attributes

Average Round Trip Time (RTT)

Max Round Trip Time

Min Round Trip Time

Pct Packet Loss

System Down time

System Degraded Time

SNMP Ping is calculated by issuing a very basic SNMP OID (1.3.6.1.2.1.1.1 – sysDescr in MIB-2) that is present in all SNMP implementations. WMI Ping is calculated by fetching a basic WMI Class (Win32_OperatingSystem) that is present in all WMI implementations.

Statistical computations (e.g. max, min, average) are done by sending 5 requests for the same object a few seconds apart. System is considered down for the polling interval if packet loss is 100%. System is considered degraded for the polling interval if packet loss is less 100% but greater than 50%.

Two reports are provided

Top Devices by SNMP RTT

Top Devices by WMI RTT

Trace route monitoring

Trace route is important for monitoring hop by hop latency between two wide area end points. It is important to know when latency for a particular hop increases significantly – this is often a precursor for internet outage. This release allows users to run trace route from any AccelOps node to any destination using the Synthetic Transaction Monitoring (STM) framework.

Details on how to set up trace route monitoring is described here. One report is provided: Top Trace Route Hops by RTT.

Log Management and Security Monitoring

Multi-tenant reporting device handling

This release allows AccelOps to handle reporting devices that are themselves multi-tenant. As an example, a Fortinet firewall can report logs for multiple organizations from the same source IP – the organizations is reported via the Virtual Domain variable. As another example, Qualys Vulnerability Scanner can report vulnerabilities for the devices belonging to multiple organizations in the same report via the qualysAssetGroup attribute.

A framework is provided to handle multi-tenant reporting devices. User can set up mapping rules specifying

attribute that specifies the external organization in the log. mapping between external organization to AccelOps organization.

Using these definitions, reporting devices are created and logs are mapped to the respective organizations. Subsequently, rules also trigger in the respective organizations. Details are in Event Organization Mapping.

Windows Agent Enhancements

This release provides several enhancements

  1. AccelOps Windows Agent and Agent Manager now communicate over HTTP(S) instead of HTTP
  2. File integrity monitoring events will now contain users that made file changes
  3. Ability to export and import license and monitoring template assignments
  4. Support for non-English locale for Windows Servers
  5. Differentiate between files and directories in AccelOps-WUA-FileMon events by using the osObjType attribute. This information is provided for the following cases: (a) create, (b) change, (c) rename but only for the new name. This information can not be provided for the following cases: (a) delete, (b) rename – for the old name.

Windows agent upgrade and configuration is covered here.

Device Support

New Support
  1. Nutanix – discovery and performance monitoring via SNMP – see here
  2. Cisco FireSIGHT integration via eStreamer API – log monitoring – see here
  3. AWS RDS and EBS – performance monitoring – see here
  4. Airlines in-flight entertainment systems monitoring
  5. Qualys Web Application Firewall log monitoring – see here
  6. CiscoWorks Network Control Manager (NCM) – log monitoring – see here
  7. Lantronix SLC Console Manager log monitoring – log monitoring – see here
  8. Vasco DigiPass – log monitoring – see here
  9. Juniper DDoS Secure – log monitoring – see here
  10. Cisco Wide Area Application Services (WAAS) – performance monitoring – see here
  11. Motorola AirDefense Wireless IDS – log monitoring – see here
  12. Motorola WiNG WLAN Access Point – log monitoring – see here
  13. Cisco Telepresence Video Communication Server – log monitoring – see here
  14. Application server log monitoring – Redhat JBoss, IBM Websphere and Oracle Weblogic – see here 15. Brocade ADX load balancer – performance monitoring – see here
  15. Ruckus Wireless LAN – performance monitoring – see here
  16. Fortinet FortiManager – performance monitoring – see here
  17. NetBotz NBRK 2000 – environmental monitoring – see here
  18. Cisco NBAR monitoring – see here
Enhanced Support

VMware SDK 5.5 API integration – AccelOps automatically uses the API for the right VMware version.

Nessus 6.0 integration – AccelOps automatically determines the right Nessus server version and uses the right API for server versions 4, 5 and 6.

Significant Enhancements

DataManager and ReportWorker module robustness

In this release, DataManager and ReportWorker do not restart under the following conditions

NFS is temporarily not available

Unable to create directories during writing or purging

The modules fall behind in reading shared buffer storage

Additional metrics on trend charts

Users can now see maximum, minimum, percentiles and simple moving averages directly in trend charts in Analytics and Dashboard sections.

Simplify Cloud and Collector health GUI

Users can select what columns to display in Cloud and Collector health pages under Admin tab. By default, fewer columns are displayed now.

Ability to manually add hosts to Application Groups

Device and Application groups are important CMDB objects that allow users to write targeted rules and reports. Until now, Application groups were only populated by discovery. This release allows users to manually add to Application groups in cases where discovery is not practical.

Important user case:

Suppose a rule triggers, namely  Excessive DNS requests from a host. The host is actually a DNS server which was not discovered. There is need to create an exception for this rule for this DNS server. Three choices –

  1. Create a rule exception for this host – sometimes this is not very manageable long term since the fact this is a DNS server can not be used in other analytics
  2. Discover the host and make sure that the host is in the DNS server group – sometimes this may not be practical.
  3. Manually add the server to the DNS server group using this feature. The DNS server group can be used for other rules and reports.

The rule would stop triggering – as desired

Set important process and critical interface definitions directly from CMDB

A important process and a critical Interface are always monitored for up/down status. Before this release, these needed to be configured from Admin > General Settings. Setting important process was difficult since one had to type in the process name, This release allows user to set these directly from CMDB > Device.

Dashboard charting enhancements

The following improvements are added

For Bar charts, the legends appear next to the charts and not at the bottom. This improves legibility.

Maximum number of displayed entries are increased form 50 to 200.

Accounting for internal and performance monitoring events

AccelOps has 3 kinds of logs/events

External logs – these count towards the licensed eps

Performance Monitoring events generated by AccelOps when it monitors a device – these also count towards the licensed eps

Internal system logs – generally reporting errors and important informational events – these do not count towards the licensed eps

Since each of these log types have to indexed, stored and since they trigger rules and reports, system performance can be affected. This release provides accurate accounting of these event types via the phstatus commands and also system provided reports. See here for details.

Ability to change event database purge/archive thresholds

By default AccelOps starts to purge (or archive if archive is set) when the free space in event database falls below 10GB. This continues until free event database space reaches 20GB. In very high event rate situations, this 10GB buffer may not suffice and database may become full. This release allows the values to be customized by the user. In phoenix_config.txt, under the phDataManager section, modify the low_space_action_threshold and low_space_warning_threshold values and restart the phDataManager module. This needs to be done at Supervisor and Worker nodes.

Ability to set remote directory renaming action during archive

When AccelOps is archiving and the destination directory already exists, then you can configure AccelOps to either rename the existing directory and archive new data to that location or skip archiving

Registration APIs

Three new APIs are provided for the following functions. For details, see here.

Register Workers to Supervisor

Register Collector to Supervisor

Register Supervisor to AccelOps License Manager

Bug Fixes / Enhancements

 

Id Severity Component Description
15147 Major System Separate Chinese language support from English versions
13921 Major Application

Server

SANS Low Sensitivity does not update by the system default API
14228 Minor System New install images for Collector and Super utilize the same OS RPM packages
14695 Minor System AccelOps can not connect to the Internet via a Proxy
14940 Minor System Address Web Server HTTP Trace/Track Method Support Cross-Site Tracing Vulnerability:

(CVE-2004-2320, CVE-2007-3008) by disabling the ability to respond to HTTP TRACE requests

15079 Minor System Secure Redis service running on Supervisor node by disallowing access from the outside
13647 Minor Application

Server

Stopped Report Generates an Application Exception when it is re-ran
14409 Normal Application

Server

Need to escape special character in rule definition xml
14274 Normal Discovery VCenter discovery – sometimes a folder shows no VMs in Dashboard > VMView
15020 Normal GUI Can’t adjust sliders on Dashboard Widgets with multiple sliders
14347 Normal GUI Add/Modify Rule Exception causes Rule to Save with a new name
14474 Normal GUI External lookup broken on Summary Dashboards
14667 Normal Performance

Monitoring

Changing a Custom WMI (not just WMI) does not take effect even after discovery
14469 Normal Device

Support

Default WMI Parser not parsing Sharepoint Event Types Correctly
13393 Normal Discovery Resolve device hostname for ping only discover devices
13811 Normal Performance

Monitoring

No Performance Data Collected After Fortigate Firewall upgrade to version 5.2.3
13626 Normal Rules Refined Sub-pattern in “Black List User Agent Match” to reduce false positives
14417 Normal Application

Server

Discovery merge need to OVERWRITE device group also instead of add on
15014 Normal GUI CMDB Device filtering does not work when Reporting IP can be resolved by DNS
15177 Normal Parser Some IOS hardware failure events do not parse
15182 Normal Performance

Monitoring

Device interface utilization may not be reported because of XML size overflow (extra large deployments)
14474 Normal GUI “External Lookup” broken on Summary Dashboards
12992 Normal Application

Server

Reverse Tunnels do not timeout as described
8515 Normal Discovery NetBotz NBRK0200 is not discovered as NetBotz
12319 Normal Performance

Monitoring

Add Provisioned disk size into PH_DEV_MON_VM_DISK_UTIL event
13954 Normal Performance

Monitoring

Memory Utilization for HPUX process reported as higher than actual Physical Memory Utilization
14576 Normal Performance

Monitoring

PH_JAVA_AGENT_ERROR due to vmDataStore perfmap wrong key
14826 Normal Application

Server

When App server is restarted, false Collector down emails are sent out
14844 Normal Application

Server

Need to turn off Beaconing report generation when Beaconing feature is turned off
14935 Normal GUI CMDB Exception Report does not correctly populate customer (Org)
7463 Enhancement GUI Allow Location information in custom email template
13068 Enhancement GUI Location CSV import needs to be able to do the following (a)intelligently find the entry, (b)merge the entries with changes that are necessary and (c) provide a UI update to tell which entries were updated with changes
13726 Enhancement GUI Use labeled bars on bar charts rather than a legend
14212 Enhancement GUI Add a CMDB report for clear rules
14585 Enhancement Application

Server

Optimize CMDB Object REST API for EventType, BizService, Device, Application groups via App Server caching technique
14701 Enhancement Application

Server

Selenium import utilizing java web driver instead of python web driver scripts
14775 Enhancement GUI In CMDB page, change “Last Updated Time” to “Last Discovered Time” and “Last Updated Method” to “Last

Discovered Method”

14781 Enhancement GUI Widget dashboard – Table View – Allow one table for whole dashboard
13809 Enhancement GUI Format report bundle PDF output – show correct page index, remove total number of pages
14989 Enhancement GUI In Rule/report filter condition, allow user to choose any event attribute attribute IN CMDB Object
14760 Enhancement GUI In Admin > Setup > Change/Performance Monitor page  – Do not show devices deleted by discovery
15149 Enhancement Rule / Query

Engine

Optimization of Rule and Report Worker for large IP Value Set
13776 Enhancement Reports CMDB Report added to show Rules with Clear Conditions
15141 Enhancement Device

Support

Merge Windows via Log Discovery Using machine GUID
13726 Enhancement GUI Using Labeled Bars on Bar-charts Rather than a Legend
14474 EnhancementGUI   Allow user to not show Event Type in Dashboard (save precious space)
15059 Enhancement Device

Support

Additional Parsing for DNS Bind (RPZ)
15091 Enhancement Device

Support

Handle Unknown event types for Ironport Mail and Web events

Current Open Bugs/Enhancements

Id Severity Component Description
8867 Major Rule Engine LAST and FIRST operators in rules do not work (may crash Rule Worker module)
11036 Major Rule Engine Rule Worker module may abort when a PctChange Expression is used
14242 Major Query Engine RBAC data conditions not enforced for SP organizations when login in via the super org and moving to another org.
15022 Major Parser Engine Parser module may stall/pause if a host name resolution is slow
11112 Major Rule Engine COUNT DISTINCT operations consume large resources for rules utilizing Anomaly Detection
14478 Major GUI Sometimes GUI pops up warning (Large amount of data stored over the boundaries) when users restore the archived data or delete the restored data
15109 Major Performance

Monitoring

Failed Custom JDBC job shows in performance page after Discovery
14766 Major Application

Server

LOG discovery does not work properly with multi-tenant reporting devices
15230 Major Parser Syslog-over-TCP does not work correctly
15247 Normal Parser AIX Parser cannot parse events correctly.
15253 Normal Parser Reporting device name is parsed wrong in LinuxInotifyParser (affects Linux file integrity monitoring via AccelOps agent)
14929 Normal Performance

Monitoring

Maintenance calendar issue – Maintenance for a device does not start at the configured time if there is a long running disabled job of another device
15068 Normal Application

Server

Dashboard Search Filtering Does not work for Clariion LUNs under Summary Tab
15231 Normal Application

Server

Generating PDF Reports over 100 Pages will drop Page Footer
15294 Normal Parser Strange device types may be created by Netflow based LOG discovery. This does not affect system operation.
14829 Normal Documentation Rule syntax invalid if use “regexp” as the sub-pattern name

 

15233 Minor Application

Server

“Validation Status” column in Admin->Event DB->Event Integrity does not allow for sorting.
15300 Minor GUI For Report Server, if you sync -> unsync -> sync is rapid succession, then the last sync may not take effect
9261 Enhancement Application

Server

Charts in exported reports (PDF format) only contain stacked charts – not line charts

 

 


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

FortiSIEM What’s New in 4.5.2

What’s new in Release 4.5.2

Bug Fixes

New Device Support

Bug Fixes

Bug ID Severity Component Description
15260 Major GUI Group By cannot be saved in Rule sub-patterns when creating / editing rules
15346 Major GUI VCenter Cluster level CPU and Memory Utilization events are not generated
15368 Major App Server Sometimes airline monitoring events have customer id 1 (Super/local) instead of correct customer id

(corresponding airline)

15398 Major System Upgrade issue – VMware pulling via Collectors – Old VMware SDK libraries (vim25-4.0.jar,vim-4.0.jar) in Collector causes VMware event pulling problems
15399 Major System Upgrade issue – missing perl-IO-Socket-SSL and perl-NetAddr-IP packages on 4.5.1 Collector causes eStreamer communication to fail from Collelctor
15400 Major Parser “use_dns_lookup=no” flag NOT working for SyslogNGParser and UnixParser
15266,

15330

Normal Parser Excessive DNS failed login causes phoenix.log to grow
15373 Normal Data Windows successful logon event parsed incorrectly as logon failure events
15317 Normal GUI Mistakenly removes Event  Receive Status for Windows Agent when user disables WMI event pull
15397 Normal Data

Manager

Occasional crash in phDataManager due to out-of-scope pointer usage
15294 Normal Parser Strange device types created in CMDB from Netflow discovery
15313 Normal App Server Exception causes App server task cache and database to go out of synch – this causes memory leak in Agent

Manager

15343 Normal App Server Creating a rule exception in Super Local will erroneously remove the corresponding entry from system watch list
15120 Minor Data Fortinet IPS Event Severity Parsing is incorrect
15249 Minor Data Some CMDB Reports containing single quote in Filter condition incorrectly displayed and do not produce correct results
15253 Minor Data Reporting device name is parsed wrong in LinuxInotifyParser
15255 Minor Data Windows Server Failed Logons report definition is incorrect because logon failure events do not have winLogonType
15265 Minor Data Reporting Device name is parsed incorrectly in agentless FIM events
15320 Minor Data AccelOps-WUA-WinLog should be parsed to syslog
15344 Minor Data Parsing error for sourcefire, cisco acs, junos
15371 Minor Data H3C syslog events have incorrect Reporting IP 0.0.7.224
15376 Minor Data One system CMDB report in Ungrouped category
15345 Minor Data Some profile rules did not report incident attributes correctly
15369 Minor Data Should not show SSH credential for Cisco FirePower in Credential tab
15285 Enhancement Data Parse  IOS-CDP-NATIVE_VLAN_MISMATCH
15372 Enhancement Enhancement Parse attribute from Windows System Time Change events and add a PCI report

New Device Support

Symantec DLP – log analysis – see here

IBM OS400 (iSeries) Log Parsing via Townsend Agent – see here

Tufin SecureTrack – log analysis – see here

IBM Guardium – log analysis – see here

 

 


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

FortiSIEM What’s New In 4.6.1

What’s New in Release 4.6.1

 

 

This release adds features and functionality in several areas.

Platform Features

Two factor authentication

Salesforce ticketing and CMDB integration

Ability to decommission a device from CMDB

Ability to export/import widget dashboard

Dark theme dashboard

Disaster recovery scripts

Performance and Availability Monitoring

Microsoft Azure compute discovery

Link usage dashboard

Log Management and SIEM

CyberArk Password Vault Integration

Salesforce CRM Audit support

Microsoft Azure Audit support

Cisco CloudAMP API support

ISO 27001 Compliance support

Device Support

New Support

Significant Enhancements

Allow users to move devices from one system defined CMDB group to another

Handle syslog over TCP

Reduce system CPU usage for SNMP V3

Keep Identity and Location database table size within limits

Allow scheduled reports to be copied to a new location

Allow queries via API to return results in csv format (gzipped)

Add a flag to control the use of winexe in discovery

Allow user to format Comment field in ServiceNow and ConnectWise for Incident Outbound

Ability to choose host name resolution mechanism during discovery

Create CMDB Report for Custom Threshold

Allow user to choose ports during SNMP port during discovery

Bug Fixes / Enhancements

Current Open Bugs/Enhancements

Platform Features

Two factor authentication

Presently the following 1-factor authentication methods are available for authenticating AccelOps GUI users:

Local authentication

External authentication via LDAP (Microsoft Active Directory and OpenLDAP), via RADIUS and Cloud Authentication via SAML (Okta)

This release makes AccelOps more secure by enabling 2-factor authentication via Duo Security. Administrator needs to tighten user’s

authentication profile by specifying two factor authentication. AccelOps will prompt the user for second factor credential after regular login. Other 2 factor authentication services e.g. Google Authenticator will be added in future releases.

Details on how to set up two factor authentication is described here.

Salesforce ticketing and CMDB integration

This release extends third party CMDB and ticketing integration by providing a plugin module for Salesforce.

Devices discovered in AccelOps can be synced to Salesforce

A ticket can be created in Salesforce when an incident triggers in AccelOps Ticket status is updated in AccelOps when it is closed in Salesforce

Details on Salesforce ticketing and CMDB integration is discussed here.

Ability to decommission a device from CMDB

Often there is a need to decommission a device and assign its IP Address to a new device. Currently, user has to delete the old device otherwise the old and the new devices will be merged as they share IP addresses. However there may be a need to keep the device in CMDB for audit purposes.

This release solves this problem by providing a separate folder for decommissioned devices. Once a device is decommissioned, it is removed from all CMDB groups and maintenance calendars, performance monitoring are stopped. The device is moved to the Decommissioned device folder. A new device with the same IP address can now be discovered and the two devices will coexist in CMDB.

For details, see here.

Ability to export/import widget dashboard

This release provides the ability to export a widget dashboard definition into an XML file. Every dashboard customization e.g. chart types, widget positioning is saved. Another user can then import the XML file and see exactly the same dashboard. This feature saves lots of work in recreating dashboards.

For details, see here.

Dark theme dashboard

This release allows users to have a dark theme dashboard. Currently this is a global setting – so all users would have the same theme.

For details, see here.

Disaster recovery scripts

A common way to perform disaster recovery is as follows

Set up an separate AccelOps cluster (Super, Workers) in a distant location – this would be a passive instance

Replicate the CMDB, SVN and event database

CMDB can be replicated by copying the exported file or by enabling PostgreSQL replication

SVN and event database can be copied over via rsynch or NFS mechanisms

This release provides a script which can bring up the passive instance and make it active. When disaster strikes, the user would do the following steps

  1. Run the script on the passive instance supervisor node.
  2. Register the passive Supervisor

Performance and Availability Monitoring

Microsoft Azure compute discovery

This release enables users to discover virtual machines in the Microsoft Azure cloud using Azure API. The API provides basic information like host name and access IP address. Therefore, SNMP and/or WMI must be used to discover the virtual machines in depth.

For details, see here.

Link usage dashboard

For perimeter network devices such as firewalls and routers, it is important to know which interfaces are busy and which traffic is consuming the most resources. This special dashboard provides this view and enables users to determine which router interfaces are overly utilized, which applications are using them and what is the QoS statistics.

For details, see here.

Log Management and SIEM

CyberArk Password Vault Integration

AccelOps needs credentials to communicate to devices. Until this release, credentials needed to be stored locally (encrypted). This release allows device credentials to be fetched from CyberArk Password Vault. This makes AccelOps more secure.

Setting up CyberArk is discussed here.

Using CyberArk for discovery is discussed here.

Configuring AccelOps for receiving CyberArk syslog is discussed here.

Salesforce CRM Audit support

Audit logs from Salesforce CRM application can now be collected by AccelOps. For details see here.

Microsoft Azure Audit support

Audit trails from Microsoft Azure cloud can now be collected by AccelOps. For details, see here.

Cisco CloudAMP API support

Rather than have a FireSIGHT Manager on premise, customers can choose to send alerts to the cloud. Using Cisco provided CloudAMP API, AccelOps is now able to collect (mostly end point) alerts from the Cisco Cloud.

For details, see here.

ISO 27001 Compliance support

This release adds reports for ISO 27001/27002 compliance specifications.

Device Support

New Support
  1. Cisco ONS – discovery, performance monitoring via SNMP and log analysis – see here
  2. Cylance Protect – log analysis – see here
  3. Pulse Secure VPN – log analysis – see here
  4. Cyphort – log analysis – see here
  5. McAfee Stonesoft IPS – log analysis – see here

Significant Enhancements

Allow users to move devices from one system defined CMDB group to another

User could already move devices from one user defined group. This release extends that functionality to system defined groups.Using this feature, user can fix device mis-classifications by discovery.

Handle syslog over TCP

AccelOps can now ingest syslog over TCP as defined in IETF RFC 6587.

Reduce system CPU usage for SNMP V3

In earlier release, the use of SNMP V3 caused significant system CPU usage during performance monitoring. This issue is resolved by reducing the number of process forks.

Keep Identity and Location database table size within limits

Identity and location entries can quickly fill up PostgreSQL database. This release allow you to control the growth of Identity and location entries by specifying two entries in the phoenix_config.txt.

PURGE_IDENTITY_LOCATION_OVER_MONTHS specifies the maximum age of Identity location database table entries. PURGE_IDENTITY_LOCATION_OVER_ROWS specifies the maximum number of rows in the Identity location database table.

When any one of the above limits are hit, the Identity location database table is purged.

Allow scheduled reports to be copied to a new location

Earlier releases allow scheduled reports to be emailed. Now the reports can be copied to be remote location via SSH.

For details, see here

Allow queries via API to return results in csv format (gzipped)

It is possible to retrieve query results via API. The results are in XML format, which is not very efficient if the result set is large. This release allows query results to be retrieved in gzipped csv files.

Add a flag to control the use of winexe in discovery

AccelOps discovery uses winexe to detect HyperV VM, Windows domain controller diagnostic (dcdiag) and replication monitoring (repadmin /replsummary). The winexe command is used to run a command on a remote windows server. However, by the nature of this command implementation by Microsoft, winexe starts a service called winexesvc on the remote server which customers do not find acceptable.

This release provides users an option to turn off winexe based discovery. This option is available in the discovery dialog.

Allow user to format Comment field in ServiceNow and ConnectWise for Incident Outbound

External ticketing systems do not have so many detailed incident attributes as AccelOps. This release enables to create a custom formatted string in the comment field in the external ticketing system.

For details, see here.

Ability to choose host name resolution mechanism during discovery

AccelOps discovers by IP addresses and used first DNS and then SNMP/WMI to get host names from IP addresses. This release allows users to control the behavior.

An discovery option now allows users to choose between DNS first (i.e. the current behavior) or SNMP/WMI first (that means SNMP/WMI then DNS).

Note – host names, once discovered are not overwritten by discovery.

Create CMDB Report for Custom Threshold

It is possible to now have a CMDB Report containing only those devices for which user has modified default thresholds.

Allow user to choose ports during SNMP port during discovery

AccelOps can now connect to SNMP via non-standard port. User can define the port during discovery. This option is available in the discovery dialog.

Bug Fixes / Enhancements

Id Severity Component Description
15147 Major System Upgrade loses user defined parsers for user defined device types
15473 Normal App Server Sync Update Config warning not clearing in System Error window
8393 Normal   Credentials can be seen in plain text view when running ps on cli during discovery and performance monitoring
15221 Normal System Backend C++ modules need to handle XML with empty attributes and not crash
15482 Enhancement App Server Add Device Annotation in CMDB Report and Device Integration Inbound
15500 Normal Performance

Monitor

Interface performance monitoring job may consume large memory when there are large number of interfaces
15975 Normal Performance

Monitor

WMI based log collection executable crashes when handle large messages containing “:”
15816 Normal Performance

Monitor

HyperV Performance monitor job may consume large amount of memory over time
15771 Enhancement System Swap sizes on all nodes must be set to memory size to avoid performance issues
15316 Normal App Server Excessive number of expired scheduled device maintenance entries causes performance issues. They are now deleted automatically.
15751 Normal App Server Cloning/creating rules does not place them under the correct Function group (e.g. Security) unless the system (or numerous processes) are restarted
14478 Normal System In some cases, system not able to restore the archived data or delete the restored data
15449 Normal System Prevent large Postgresql log files in /cmdb/data/pg_log/ from filling the /cmdb disk
15969 Normal Database Baseline profile schema upgrade error causes excessive loging and failed base lines in some cases
15403 Enhancement GUI RBAC: Report Server Sync button – disallow in “Run” mode, allow in Edit mode
15468  Normal Performance

Monitor

Java vulnerability pulling agents can randomly fail because of incorrect way of checking for potentially non-existent parameters in the vulnerability scan reports.
15309  Enhancement Database, App

Server

Add Reporting Device Name to an incident. Show this field in Incident dashboard. Make sure Incident XML has this field.
15875 Normal App Server Incident ID grew over time and results in an overflow causing incident report export to fail
15499 Normal GUI Add “Device Type” in Incident XML for Incident Outbound Integration
16002 Normal Parser Event rate in PH_SYSTEM_DEVAPP_EVENTS_PER_SEC is extremely high
15489 Normal Parser  PH_DEV_MON_HW_TEMP of  HP Comware switch misses hardware components.
15197 Normal System EMC VNX connectivity test stops working after upgrade
16080 Normal System Need to add Kafka configuration for VA after upgrading to 4.5
15466 Normal Parser WinOSWmiParser not parsing event id’s 4800 and 4801 correctly
15988 Normal Data SNMP Service Unavailable incident can not triggered

Current Open Bugs/Enhancements

Id Severity Component Description
8867 Normal Rule Engine LAST and FIRST operators in rules do not work (may crash Rule Worker module)
11036 Normal Rule Engine Rule Worker module may abort when a PctChange Expression is used
14242 Normal Query Engine RBAC data conditions not enforced for SP organizations when login in via the super org and moving to another org.
15022 Normal Parser Engine Parser module may stall/pause if a host name resolution is slow
11112 Normal Rule Engine COUNT DISTINCT operations consume large resources for rules utilizing Anomaly Detection
14478 Normal GUI Sometimes GUI pops up warning (Large amount of data stored over the boundaries) when users restore the archived data or delete the restored data
15109 Normal Performance

Monitoring

Failed Custom JDBC job shows in performance page after Discovery
15247 Normal Parser AIX Parser cannot parse events correctly.

 

15253 Normal Parser Reporting device name is parsed wrong in LinuxInotifyParser (affects Linux file integrity monitoring via AccelOps agent)
14929 Normal Performance

Monitoring

Maintenance calendar issue – Maintenance for a device does not start at the configured time if there is a long running disabled job of another device
15068 Normal Application

Server

Dashboard Search Filtering Does not work for Clariion LUNs under Summary Tab
15231 Normal Application

Server

Generating PDF Reports over 100 Pages will drop Page Footer
15233 Minor Application

Server

“Validation Status” column in Admin->Event DB->Event Integrity does not allow for sorting.
15300 Minor GUI For Report Server, if you sync -> unsync -> sync is rapid succession, then the last sync may not take effect
9261 Enhancement Application

Server

Charts in exported reports (PDF format) only contain stacked charts – not line charts

 

 


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

FortiSIEM What’s New In 4.6.3

What’s new in Release 4.6.3

Starting 4.6.3, AccelOps has been re-branded as FortiSIEM.

Special upgrade procedure

Features

FortiSIEM re-branding

Enforce TLS 1.2 for tighter security

Windows Agent Enhancements (Windows Agent and Agent Manager 2.0)

Bug Fixes / Enhancements

Current Open Issues

Special upgrade procedure

Features

FortiSIEM re-branding

From this release onward, AccelOps will be branded FortiSIEM.

Enforce TLS 1.2 for tighter security

FortiSIEM web servers now only advertise TLS1.2. All FortiSIEM components now communicate using secure TLS 1.2 protocol. This includes the following communications

Collector to Super/Worker

Worker to Super

Browser to Super

Windows Agent to Agent Manager

Agent Manager to Collector and Super

Windows Agent Enhancements (Windows Agent and Agent Manager 2.0)

This release contains the following Windows Agent enhancements.

  1. Enhanced user file monitoring: Windows Agent allows users to monitor changes in custom files. This release enhances this feature in the following ways.
    1. Allow user to specify a custom string for each monitored file. The specified user defined string would be included in the event type as a signature for that file. For example, if user is monitoring a special MyApp1 log file, then user can specify a custom string e.g. MyApp1 and the event type would be AO-WUA-UserFile-MyApp1. This approach allows the user to write a specific parser for each monitored log file by specifying the string AO-WUA-UserFile-MyApp1 in the event format recognizer.
    2. Allow wildcards in monitored file name; e.g. *radius.log. This enhancement allows for dynamically named log files including dates in file name. For example DHCP and RADIUS files are generated every day and the file names contain the date e.g. 012415radius.log.
  2. Ability to monitor any file in Windows Event Manager tree: Prior to this release AccelOps only monitored specific log files in the Windows Event Manager tree, namely Security, Application, Performance events, DNS logs, DHCP logs etc. This release provides the capability to monitor any file in Windows Event Manager tree. User needs to choose the desired Windows Event Manager folder and FortiSIEM Agent will start monitoring events for that application. The corresponding event type will contain the folder name to distinguish it from events from other folders.
  3. Windows CD/DVD/USB monitoring: FortiSIEM can now detect insertion/removal and certain file read/write activity on external media such as USB and CD/DVD. Specifically, the following cases are covered in this release
    1. Detect when external media such as USB, CD, DVD is inserted
    2. Detect when external media such as USB, CD, DVD is removed
    3. Detect when a file is written to USB
  4. Enhanced File integrity and Registry change monitoring: This release contains the following enhancements:
    1. User can exclude directories while specifying files to be monitored, e.g. monitor “C:\System32” but exclude “C:\System32\Log” b.  Include the process name triggered file modification in FortiSIEM events
    2. Allow environment variables in the file path definition
  5. Monitoring Template and License Assignment improvements: for details see here.
    1. User can define multiple monitoring templates per host, e.g. OS monitoring template, Application 1 monitoring template, Application 2 monitoring template etc.
    2. User can assign templates and licenses for large number of hosts with much fewer clicks than earlier releases
    3. A searchable tabular display of Host to license and template assignments.
  6. Allow multiple power shell and WMI scripts per monitoring template. Prior releases only allowed one script per template.
  7. Create Alerts when an Agent is stopped, uninstalled or unresponsive. This allows users to report and detect these potential policy violations.

Bug Fixes / Enhancements

Bug

ID

Severity Component Description
13156 Major System In high eps environment, license checking may fail because of the inability to fork new processes, resulting in workers to become unavailable.
16125 Major App Server The feature “Fire Incidents for Approved devices only” does not work correctly
16555 Major App Server User added widgets to dashboards in Super global mode always run in adhoc query mode (instead of inline mode), making dashboards run slowly
16433 Normal Parser Netflow Application from Fortinet firewalls is not handled correctly
16248 Normal Parser Syslog over TCP does not work correctly – logs are not complete
16442 Normal App Server Summary dashboard loads slowly when there are large number of devices with location specified
16586 Normal App Server Incident Notification over XML over HTTPS Notification does not work correctly because of handshake failure.
16286 Enhancement GUI Add search filter for collectors in Admin > General Settings > Event Org mapping > Add > Collectors
16567 Normal Performance

Monitoring

AWS RDS monitoring sometimes does not work correctly.
16470 Normal Rule Engine Incidents may not trigger when Event Dropping Rules refer to stale CMDB Objects
16581 Normal GUI ‘Copy to remote’ option is turned off for ‘Scheduled for’ when user schedules a report in Super/global mode.
16530 Normal Performance

Monitoring

SNMP V3 with AES not working after upgrading to 4.6.2
16481 Normal Performance

Monitoring

STM job credential manipulation may cause discover and performance monitor to crash. This is first introduced in 4.6.2 enhancement that obfuscates user names and password in system calls from back end processes
16093 Enhancement App Server Report names are not meaningful when they are copied over to an external location in “Copy to remote” feature
16251 Enhancement GUI, Parser Allow comma separated External Org in Event Org Mapping. This allows for multiple external organizations to map to a single FortiSIEM organization.

Current Open Issues

Id Severity Component Description
8867 Normal Rule Engine LAST and FIRST operators in rules do not work (may crash Rule Worker module)
11036 Normal Rule Engine Rule Worker module may abort when a PctChange Expression is used
14242 Normal Query Engine RBAC data conditions not enforced for SP organizations when login in via the super org and moving to another org.
15022 Normal Parser Engine Parser module may stall/pause if a host name resolution is slow. Work around for now is to disable host name resolution.
11112 Normal Rule Engine COUNT DISTINCT operations consume large resources for rules utilizing Anomaly Detection
14478 Normal GUI Sometimes GUI pops up warning (Large amount of data stored over the boundaries) when users restore the archived data or delete the restored data
15109 Normal Performance

Monitoring

Failed Custom JDBC job shows in performance page after Discovery
15247 Normal Parser AIX Parser cannot parse events correctly.
15253 Normal Parser Reporting device name is parsed wrong in LinuxInotifyParser (affects Linux file integrity monitoring via AccelOps agent)
14929 Normal Performance

Monitoring

Maintenance calendar issue – Maintenance for a device does not start at the configured time if there is a long running disabled job of another device
15068 Normal Application

Server

Dashboard Search Filtering Does not work for Clariion LUNs under Summary Tab
15231 Normal Application

Server

Generating PDF Reports over 100 Pages will drop Page Footer
15233 Minor Application

Server

“Validation Status” column in Admin->Event DB->Event Integrity does not allow for sorting.
15300 Minor GUI For Report Server, if you sync -> unsync -> sync is rapid succession, then the last sync may not take effect
9261 Enhancement Application

Server

Charts in exported reports (PDF format) only contain stacked charts – not line charts

What’s new in Release 4.6.2

 

This release contains the following bugs fixes.

Bug Fixes

Bug

ID

Severity Component Description
15161 Major Performance Monitor,

Discovery

The ability for AccelOps to connect to SNMP on a UDP port different than default 161, a 4.6.1 feature, does not work correctly.
16235 Major Parser WMI based pulling of Windows Security, Application and System logs truncates some event attributes. So certain windows eports and rules may not work correctly.
16249 Minor Discovery Default hardware serial numbers (like “None” in CentOS) causes two devices to be merged incorrectly during discovery
16237 Minor Performance

Monitoring

Long running performance monitoring jobs may cause new performance monitoring jobs to not take effect

 

 


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

FortiSIEM What’s New In 4.7.1

What’s new in Release 4.7.1

Features

HTML5 based GUI for Incident

You can logon to the HTML5 version of Incident page using the link https://<SupervisorIP>/phoenix/html.

For details see here.

Malware URL threat feed

Previous releases allowed users to import Malware domain, IP, file hashes and Anonymity Networks as external threat intelligence feed. This release extends this functionality to Malware URLs.

For details, see here.

Syslog over TLS

This release enables FortiSIEM to receive encrypted Syslog over TLS.

For details, see here.

Device Audit framework

FortiSIEM discovers devices in depth, collects various performance/availability metrics, parses logs, traps and triggers rules. This release provides users a framework to run an audit on devices based on the collected information. Audit criteria can be based on

OS version

Installed software version

A set of reports representing audit violations

A set of rules triggering incidents representing audit violations

User can define audit criteria and run a check against devices – either on-demand or periodically on a schedule. The results can be displayed on GUI, exported as PDF from GUI or emailed with PDF attachments.

For details, see here.

Device Support – New

Aruba Switches – discovery (Bug 15800) Alertlogic IPS – log parsing (Bug 16250)  AWS Elastic Load Balancer – log parsing (Bug 15752)

Device Support – Enhancements

F5 load balancer – detailed performance monitoring

Fortinet FortiOS – more detailed data collection and trap parsing

Aruba Clearpass Manager – more detailed log parsing (Bug 15542)

Checkpoint GAIA – monitor memory using UCD MIBs (Bug 16203)

HP/UX – more detailed syslog parsing (Bug 15565)

InfoBlox – more detailed syslog parsing (Bug 16121, Bug 16191)

Dell Equallogic – more detailed syslog parsing (Bug 15433)

TrendMicro Officescan – more detailed syslog parsing (Bug 16122)

Checkpoint FireWall-1 – parsing fix (Bug 16119)

Microsoft Windows – Added event id 4769 (Bug 16191)

Microsoft Windows – Added event id 6274, 6272 (Bug 12163)

Microsoft Windows – Added event id 5137 (Bug 7429)

Juniper SecureAccess – parser enhancement (Bug 16035)

Palo Alto Firewall – parser enhancements (Bug 16727, 16169)

Fortinet FortiOS  Firewall – parser enhancements (Bug 16554)

Symantec Endpoint Control – parser enhancements (Bug 16210)

F5 ASM – parser enhancements (Bug 16726)

McAfee Stonesoft IPS – parser enhancements (Bug 16729)

Cisco Call Manager – parser enhancements (Bug 16395)

Cisco ACS Parser – parser enhancement (Bug 15550)

Imperva SecureSphere – parser improvements (Bug 16036)

HP Procurve – syslog parsing enhancement (Bug 12072)

Bug Fixes / Enhancements

Bug

ID

Severity Component Description
16779 Minor App Server A user cannot change their own password if the CMDB Tab view is restricted from them
16767 Minor System File rename error on cross-partition operation may lead to event database archive failure
16340 Minor Parser Incorrectly formatted Netflow packets can cause parser module to crash
16460 Minor App Server Users who do not have permissions for Admin > Discovery can not launch discovery from CMDB
16009 Minor App Server User created custom types (device, event, attribute) are created as Origin = System after upgrade
16655 Minor App Server Empty “Time” in Incident Notification Policy can cause notification policy to not trigger
16067 Minor GUI Can not add more than 100 devices to a CMDB Device folder
16654 Minor GUI Can not handle CMDB Reports with filter conditions containing strings with spaces, e.g. Installed Software Name =

‘Attack Definition’

16764 Minor App Server Incident Notification Policy may some times trigger twice for the same incident id
15296 Enhancement App Server Ability tp export test connectivity error, discovery error and discovery change delta results as PDF reports
16898 Minor App Server Run script notification may sometimes fail to run
16055 Minor Parser The ‘vulnSolution’ event attribute populated from Vulnerability pulling agents such Qualys and Nessus need to allow for URLs.
16007 Minor App Server An exception may happen during clear incident processing resulting in the clear incident not getting stored
16867 Enhancement Parser SSH script for Foundry switches fails when the switch is configured to login to enable mode directly without typing in

“enable; username; password”

16870 Minor Performance

Monitoring

For custom SNMP monitoring, snmpbulkwalk command does not working for some OIDs while snmpwalk works
15527 Enhancement GUI Allow users to edit the same property for multiple devices in one shot by simply multi-selecting the devices and entering new values
16382 Enhancement App Server On CMDB Reports, Add ‘Processor Name’ attribute to “Server Hardware: Processor” report
16431 Enhancement Parser System error message “Success ratio too low” is enhanced to report only when a large of retry attempts have occurred

Current Open Issues

Id Severity Component Description
8867 Normal Rule Engine LAST and FIRST operators in rules do not work (may crash Rule Worker module)
11036 Normal Rule Engine Rule Worker module may abort when a PctChange Expression is used
14242 Normal Query Engine RBAC data conditions not enforced for SP organizations when login in via the super org and moving to another org.
15022 Normal Parser Engine Parser module may stall/pause if a host name resolution is slow. Work around for now is to disable host name resolution.
11112 Normal Rule Engine COUNT DISTINCT operations consume large resources for rules utilizing Anomaly Detection
14478 Normal GUI Sometimes GUI pops up warning (Large amount of data stored over the boundaries) when users restore the archived data or delete the restored data
15109 Normal Performance

Monitoring

Failed Custom JDBC job shows in performance page after Discovery
15247 Normal Parser AIX Parser cannot parse events correctly.
15253 Normal Parser Reporting device name is parsed wrong in LinuxInotifyParser (affects Linux file integrity monitoring via AccelOps agent)
14929 Normal Performance

Monitoring

Maintenance calendar issue – Maintenance for a device does not start at the configured time if there is a long running disabled job of another device
15068 Normal Application

Server

Dashboard Search Filtering Does not work for Clariion LUNs under Summary Tab
15231 Normal Application

Server

Generating PDF Reports over 100 Pages will drop Page Footer
15233 Minor Application

Server

“Validation Status” column in Admin->Event DB->Event Integrity does not allow for sorting.
15300 Minor GUI For Report Server, if you sync -> unsync -> sync is rapid succession, then the last sync may not take effect
9261 Enhancement Application

Server

Charts in exported reports (PDF format) only contain stacked charts – not line charts

 

 


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

FortiSIEM What’s New 4.7.2

What’s new in Release 4.7.2

Device Support

FortiSandbox – discovery, performance monitoring, log analysis and external threat intelligence (see here)

FortiWeb – discovery, performance monitoring and log analysis (see here)

FortiMail – log analysis (see here)

MalwareBytes – log analysis (see here)

Sophos UTM – log analysis (see here)

Bug Fixes

Bug ID Severity Component Description
17552 Major System Patch Linux Kernel Local Privilege Escalation Vulnerability (“Dirty COW”) – CVE-2016-5195
15161 Major App Server FortiSIEM users cannot change their own passwords if they are read only users or were restricted by RBAC from viewing or making changes to CMDB users page
17025 Major Parser Cisco ASA parser code introduced in 4.5.1 leaks memory
17216,

17056

Major System FortiSIEM hangs during upgrade and reboot if there is no internet connectivity. This is because in 4.7.1, OS update was done during upgrade and reboot. This release provides two solutions: (1) OS upgrade via yum update now only happens during upgrade and not during reboot and (2) FortiSIEM goes to repositories set up in AWS Cloudfront AWS edge locations listed here (https://aws.amazon.com/cloudfront/details/#edge-locations) depending on where the FortiSIEM node is connecting from. The Cloudfront CDN distribution is created and controlled by FortiSIEM engineering. If the connection to this edge location fails, it connects to origin server ima ges-os.accelops.net which is hosted by FortiSIEM engineering in AWS
17466 Major Rule Engine Rule Engine sometimes crashes while evaluating FIRST and LAST aggregation operators
16991 Normal Performance

Monitor

Sometime Java Agent has too many open files
17290 Normal Parser AIX log Parser incorrectly parses reporting device name
15868 Normal Performance

Monitoring

Palo Alto Firewall configuration pulling SSH script not logging out
16969 Normal System FortiSIEM Worker ssl.conf is overwritten during upgrade – e.g. if FortiSIEM Worker is configured to use valid CA certificates, these are overwritten during an upgrade to use self-signed. FortiSIEM Supervisor works correctly.
16984 Normal System Re-registered license not getting updated in Worker and Report Server.
16992 Normal Performance

Monitoring

Java agents (e.g. SQL based monitoring) can result in too many open files

 

16995 Normal Rule Engine While testing rules, Rule Master module may time out if the rule test evaluates to FALSE. RuleMaster never reports the status to the GUI.
17008 Normal GUI White labeling does not work correctly in HTML5 GUI
17058 Normal GUI User can no longer approve multiple CMDB devices at a time.
17068 Normal GUI Ticketing system GUI can not load tickets if any ticket does not have a due date
17097 Normal Performance

Monitoring

FortiGate SSH based commands for Audit do not work when VDOMs are configured
17114 Normal App Server CMDB replication setting in postgresql.conf on both Super and Report Server lost after upgrade
17115 Normal System Prevent event loss during eps surge by adding another warning period to elastic eps enforcement
17352 Normal GUI Sometimes, the list of users in Assigned To in a ticket created from incident, may not be shown properly
17354 Normal Query Engine Sometimes Incident Query with Incident Reporting IP IN A Device Group does not return result.
17380 Normal Parser Device type in TrendMicro Deep Security Manager parser is incorrect.
17382 Normal Discovery Can not connect to a device via Telnet/SSH when user name is empty but password and enable password is set
17387 Normal Discovery Custom device discovery does not work when discovered device type is Generic Unix or Generic Linux.
17409 Normal GUI CMDB > Device > Link usage does not show data for non-FortiGate devices
17483 Normal Discovery SDEE based Test Connectivity to Cisco IPS does not work for Cisco IPS 7.0 and earlier that does not support

TLS 1.2

17076 Enhancement Data Some Cylance Protect syslog can not be parsed
17092 Enhancement Performance

Monitoring

Allow a higher priority queue for Airline log monitoring
17098 Enhancement GUI Remove “Forticare” from default exported Audit report name
17115 Enhancement Device Support Extend IBM Townsend parser
17248 Enhancement Device Support Update FortiGate IPS Event types (Signatures)
17255 Enhancement Device Support Update Forcepoint (previously McAfee Stonesoft) parser
17405 Enhancement Device Support Update F5 ASM parser
17057 Enhancement Device Support Update Nginx parser

Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!