You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

FortiGate一小时未向Wazuh发日志时触发邮件告警的规则问题

FortiGate防火墙日志中断告警规则修复方案

需求为当FortiGate防火墙一小时未向Wazuh发送日志时触发告警邮件,但使用ChatGPT生成的规则持续报错,原规则如下:

<rule id="132000" level="10">
      <if_sid>44601,44602,44603,44604,44605,44606,44607,44608,44609,44610,44611,44612,44613,44614,44615,44616,44617,44618,44619,44620,44621,44623,44625,44626,44627,44628,44629,44630,44631,81606,81607,81608,81609,81610,81611,81612,81613,81614,81615,81616,81617,81618,81619,81620,81621,81622,81623,81624,81625,81626,81627,81628,81629,81630,81631,81632,81633,81634,81635,81636,81637,81638,81639,81640,81642,81643,81644,81645,81646</if_sid> 
      <field name="received_at" operator="less_equal">-1h</field>
      <description>FortiGate Firewall Log Delay</description>
      <group>fortigate_log</group>
      <options>no_caching,no_alert</options>
      <program_name>FortiGate</program_name>
      <email_notification>
        <subject>Wazuh Alarm: FortiGate Firewall Log Delay</subject>
        <to>admin@test.com</to>
        <html>yes</html>
        <body>The FortiGate firewall is not sending logs. Log delay has occurred.</body>
      </email_notification>
    </rule>

原规则核心错误分析

  1. 逻辑方向错误:received_at字段仅对已接收的日志生效,当FortiGate停止发送日志时,没有符合<if_sid>的日志触发规则,该条件永远无法匹配。
  2. 规则结构违规:
    • <program_name>属于规则条件,应嵌套在<condition>标签内,而非独立存在。
    • Wazuh规则不支持直接嵌套<email_notification>标签,邮件告警需通过全局配置或主动响应触发。
  3. 选项矛盾:no_alert选项会直接抑制告警生成,与需求完全冲突。

正确实现方案

方案一:利用Wazuh内置设备可用性监测

Wazuh默认支持设备活跃度检测,针对远程日志源(如FortiGate),可通过以下步骤配置:

  1. 确保FortiGate已完成日志采集配置,能正常向Wazuh发送日志,且设备在Wazuh控制台可见。
  2. 在/var/ossec/etc/rules/local_rules.xml中添加自定义规则:
<rule id="132000" level="10">
  <if_sid>507</if_sid> <!-- 匹配Wazuh内置的设备失联规则 -->
  <match>FortiGate</match> <!-- 替换为你的FortiGate设备名称 -->
  <description>FortiGate防火墙已超过1小时未发送日志</description>
  <group>fortigate_log,availability</group>
</rule>
  1. 配置全局邮件通知,修改/var/ossec/etc/ossec.conf:
<global>
  <email_notification>yes</email_notification>
  <email_to>admin@test.com</email_to>
  <smtp_server>你的SMTP服务器地址</smtp_server>
  <email_from>wazuh-alerts@your-domain.com</email_from>
</global>
  1. 调整设备失联阈值,在ossec.conf的<remote>或<agentless>模块中设置:
<remote>
  <connection>syslog</connection>
  <port>514</port>
  <protocol>udp</protocol>
  <timeout>3600</timeout> <!-- 1小时无日志则标记为失联 -->
</remote>

方案二:统计规则检测日志缺失

通过统计指定时间内FortiGate日志的匹配数量,为0时触发告警:

<rule id="132001" level="10">
  <if_matched_sid>44601,44602,...,81646</if_matched_sid> <!-- 保留原规则中的所有FortiGate规则SID -->
  <frequency>1</frequency> <!-- 统计周期内至少需要1条日志,否则触发告警 -->
  <timeframe>3600</timeframe> <!-- 统计周期为1小时 -->
  <description>FortiGate防火墙在过去1小时内未发送任何日志</description>
  <group>fortigate_log</group>
  <options>no_full_log</options>
</rule>

注意:需确保Wazuh统计引擎处于启用状态,该规则依赖日志匹配统计功能。

关键注意事项

  • 必须保证FortiGate日志采集链路正常,否则所有监测规则都无法生效。
  • SMTP服务器需配置正确的认证信息(如用户名、密码),避免邮件发送失败。
  • 修改规则或配置后,需重启Wazuh管理器使配置生效:systemctl restart wazuh-manager

内容的提问来源于stack exchange,提问作者John Niyazi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 21:25:09