Fortinet white logo
Fortinet white logo

FortiDLP Administration Guide

Agent offline warning

Agent offline warning

The Agent offline warning indicates when nodes are offline for longer than a configurable period of time.

With this warning, nodes that are offline for longer than the defined threshold will be reported as offline in the Nodes module's dashboard. For increased visibility, FortiDLP can also generate detections when nodes are offline for longer than the threshold.

The Agent offline warning is configurable within Admin settings > Agent configuration. There, you can:

  • set the offline threshold
  • specify entities to which the Agent offline warning applies
  • enable/disable offline node detections, and
  • specify the risk score and tags to assign to offline node detections.
Tooltip

The risk score value you provide also determines the severity level of a detection. A severity displays alongside a detection to help security analysts best allocate their time to threat response.

Agent offline warning

Agent offline warning

The Agent offline warning indicates when nodes are offline for longer than a configurable period of time.

With this warning, nodes that are offline for longer than the defined threshold will be reported as offline in the Nodes module's dashboard. For increased visibility, FortiDLP can also generate detections when nodes are offline for longer than the threshold.

The Agent offline warning is configurable within Admin settings > Agent configuration. There, you can:

  • set the offline threshold
  • specify entities to which the Agent offline warning applies
  • enable/disable offline node detections, and
  • specify the risk score and tags to assign to offline node detections.
Tooltip

The risk score value you provide also determines the severity level of a detection. A severity displays alongside a detection to help security analysts best allocate their time to threat response.