Current Thresholds for Health Status
The following table provides information on what normal thresholds are for certain Health JSON attributes.
Health JSON Attribute |
Applicability |
Threshold |
---|---|---|
CPU Utilization |
All nodes |
|
Memory Utilization |
All nodes |
|
Swap Space Utilization |
All nodes |
|
Disk Utilization |
All nodes; skips /data, data-clickhouse |
|
I/O Utilization |
All nodes |
|
Process Health |
All nodes |
|
Event Pipeline |
Collector only |
This indicates whether queues are building up in Collectors.
|
Event Pipeline |
Worker only |
This indicates whether queues are building up in Workers and may be caused by Workers slow in ingesting events to storage.
|
Shared Store |
Worker, Supervisor |
This indicates that some FortiSIEM processes are slow in processing events and may eventually block the writer phParser process from ingesting events. Events may eventually be lost.
|
Last Status Updated |
All nodes |
This is based on the health updates between Collector and Supervisor; Worker and Supervisor; and Instance Supervisor and FortiSIEM Manager.
|
Last Event Time |
Collector |
This information is sent by each Worker to Supervisor based on what each Worker receives from Collectors. This detects whether Collectors are falling behind in sending events to Workers. This may be caused by Workers slow in ingesting events to storage or Collectors slow processing events and uploading to Workers.
|
Last File Received |
Collector |
This information is sent by each Worker to Supervisor based on what each Worker receives from Collectors. This may be caused by Workers slow in ingesting events to storage or Collectors slow processing events and uploading to Workers.
|