FortiGate一小时未向Wazuh发日志时触发邮件告警的规则问题
FortiGate防火墙日志中断告警规则修复方案
需求为当FortiGate防火墙一小时未向Wazuh发送日志时触发告警邮件,但使用ChatGPT生成的规则持续报错,原规则如下:
<rule id="132000" level="10"> <if_sid>44601,44602,44603,44604,44605,44606,44607,44608,44609,44610,44611,44612,44613,44614,44615,44616,44617,44618,44619,44620,44621,44623,44625,44626,44627,44628,44629,44630,44631,81606,81607,81608,81609,81610,81611,81612,81613,81614,81615,81616,81617,81618,81619,81620,81621,81622,81623,81624,81625,81626,81627,81628,81629,81630,81631,81632,81633,81634,81635,81636,81637,81638,81639,81640,81642,81643,81644,81645,81646</if_sid> <field name="received_at" operator="less_equal">-1h</field> <description>FortiGate Firewall Log Delay</description> <group>fortigate_log</group> <options>no_caching,no_alert</options> <program_name>FortiGate</program_name> <email_notification> <subject>Wazuh Alarm: FortiGate Firewall Log Delay</subject> <to>admin@test.com</to> <html>yes</html> <body>The FortiGate firewall is not sending logs. Log delay has occurred.</body> </email_notification> </rule>
原规则核心错误分析
- 逻辑方向错误:
received_at字段仅对已接收的日志生效,当FortiGate停止发送日志时,没有符合<if_sid>的日志触发规则,该条件永远无法匹配。 - 规则结构违规:
<program_name>属于规则条件,应嵌套在<condition>标签内,而非独立存在。- Wazuh规则不支持直接嵌套
<email_notification>标签,邮件告警需通过全局配置或主动响应触发。
- 选项矛盾:
no_alert选项会直接抑制告警生成,与需求完全冲突。
正确实现方案
方案一:利用Wazuh内置设备可用性监测
Wazuh默认支持设备活跃度检测,针对远程日志源(如FortiGate),可通过以下步骤配置:
- 确保FortiGate已完成日志采集配置,能正常向Wazuh发送日志,且设备在Wazuh控制台可见。
- 在
/var/ossec/etc/rules/local_rules.xml中添加自定义规则:
<rule id="132000" level="10"> <if_sid>507</if_sid> <!-- 匹配Wazuh内置的设备失联规则 --> <match>FortiGate</match> <!-- 替换为你的FortiGate设备名称 --> <description>FortiGate防火墙已超过1小时未发送日志</description> <group>fortigate_log,availability</group> </rule>
- 配置全局邮件通知,修改
/var/ossec/etc/ossec.conf:
<global> <email_notification>yes</email_notification> <email_to>admin@test.com</email_to> <smtp_server>你的SMTP服务器地址</smtp_server> <email_from>wazuh-alerts@your-domain.com</email_from> </global>
- 调整设备失联阈值,在
ossec.conf的<remote>或<agentless>模块中设置:
<remote> <connection>syslog</connection> <port>514</port> <protocol>udp</protocol> <timeout>3600</timeout> <!-- 1小时无日志则标记为失联 --> </remote>
方案二:统计规则检测日志缺失
通过统计指定时间内FortiGate日志的匹配数量,为0时触发告警:
<rule id="132001" level="10"> <if_matched_sid>44601,44602,...,81646</if_matched_sid> <!-- 保留原规则中的所有FortiGate规则SID --> <frequency>1</frequency> <!-- 统计周期内至少需要1条日志,否则触发告警 --> <timeframe>3600</timeframe> <!-- 统计周期为1小时 --> <description>FortiGate防火墙在过去1小时内未发送任何日志</description> <group>fortigate_log</group> <options>no_full_log</options> </rule>
注意:需确保Wazuh统计引擎处于启用状态,该规则依赖日志匹配统计功能。
关键注意事项
- 必须保证FortiGate日志采集链路正常,否则所有监测规则都无法生效。
- SMTP服务器需配置正确的认证信息(如用户名、密码),避免邮件发送失败。
- 修改规则或配置后,需重启Wazuh管理器使配置生效:
systemctl restart wazuh-manager
内容的提问来源于stack exchange,提问作者John Niyazi
相关产品推荐
相关产品推荐

