Fortinet white logo
Fortinet white logo

User Guide

26.1.0

Parent-child alerting for Fabric and SNMP devices

Parent-child alerting for Fabric and SNMP devices

The following logic changes have been implemented to improve alert visibility for child devices:

  • Child incident alerts are triggered normally, except in the following cases:

    • If the parent device is a Fabric or SNMP device and has an active Heartbeat incident, alerts for child incidents are silenced.

    • If the parent device is not a Fabric or SNMP device, but has an active Ping incident, alerts for child incidents are silenced.

Note: Parent/child relationships do not affect the creation of incidents on child devices. Those will always be generated. The only impact is on whether alert notifications for child incidents are silenced based on the conditions above.

Example:

If a FortiGate device has a high CPU usage alert (a non-heartbeat condition) but is otherwise reachable, it will not suppress notifications for incidents on its child devices. Those alerts will be sent as usual.

Previous Behavior

Previously, if any metric on a parent device was in an alert state, all child device incidents were still created, but all alert notifications were suppressed. This may cause critical child alerts to be missed, especially in SNMP and Fabric environments.

Parent-child alerting for Fabric and SNMP devices

Parent-child alerting for Fabric and SNMP devices

The following logic changes have been implemented to improve alert visibility for child devices:

  • Child incident alerts are triggered normally, except in the following cases:

    • If the parent device is a Fabric or SNMP device and has an active Heartbeat incident, alerts for child incidents are silenced.

    • If the parent device is not a Fabric or SNMP device, but has an active Ping incident, alerts for child incidents are silenced.

Note: Parent/child relationships do not affect the creation of incidents on child devices. Those will always be generated. The only impact is on whether alert notifications for child incidents are silenced based on the conditions above.

Example:

If a FortiGate device has a high CPU usage alert (a non-heartbeat condition) but is otherwise reachable, it will not suppress notifications for incidents on its child devices. Those alerts will be sent as usual.

Previous Behavior

Previously, if any metric on a parent device was in an alert state, all child device incidents were still created, but all alert notifications were suppressed. This may cause critical child alerts to be missed, especially in SNMP and Fabric environments.