How To Integrate Logs Into Service Now
Troubleshooting
Fault messages in the FortiAnalyzer Integration App GUI and in the ServiceNow Application Logs describe the trouble and ordinarily incorporate recommendations to right it.
Connection issues
To troubleshoot connection problems between FortiAnalyzer and the FortiAnalyzer Integration App:
- In FortiAnalyzer, go to Organization Settings > Admin > Administrators.
- Click the account used for integration with the FortiAnalyzer Integration App and check that the settings are correct.
Encounter Setting Up FortiAnalyzer.
- Click the account used for integration with the FortiAnalyzer Integration App and check that the settings are correct.
- Cheque that you lot have ready upwards JSON-RPC permission correctly.
Ensure the Username tin can be found in FortiAnalyzer and has JSON-RPC permission.
Meet Setting Upward FortiAnalyzer.
- Get to the FortiAnalyzer Integration App System Properties.
- Check that the connection settings are correct, especially the domain proper name, port number, ADOMs, and API credentials.
- Ensure the Domain HTTPS link is correct.
- Ensure a trusted, signed SSL document is installed.
- Ensure the port number is correct.
- Ensure the password is correct.
See Setting upward the FortiAnalyzer Integration App.
If connectedness settings are incorrect, the app displays an fault message when you click Salve.
- Cheque that you are using a supported firmware version.
- Check that the connection settings are correct, especially the domain proper name, port number, ADOMs, and API credentials.
- Cheque that the FortiAnalyzer is missing a document, or the certificate is incomplete. ServiceNow requires a trusted certificate on FortiAnalyzer to establish a secured connection.
- In ServiceNow, go to Application Log > Errors. The following error may bespeak the certificate is incomplete:
fileName: ;line:0;errorMessage:org.apache.commons.httpclient.HttpException:SSLPeerUnverifiedException
- Utilize a tertiary-party service such every bit digicert or sslshopper to identify the errors on the FortiAnalyzer side.
- In FortiAnalyzer, get to System Settings > Certificates, to fix the certificate issues, such every bit adding an intermediate CA certificate.
- In ServiceNow, go to Application Log > Errors. The following error may bespeak the certificate is incomplete:
To troubleshoot consequence logs that are non updating:
Event logs are non automatically updated after a FortiAnalyzer service outage when "Fetch events from FortiAnalyzer ADOMs automatically" is enabled. To resume updates later service is restored, run the Run_FetchFAZEvents script.
Y'all must have an admin role to perform this task. |
- Go to Organization Definition > Scheduled Jobs, or type
scheduled jobs
in the organisation explorer. - Blazon
*faz
in the Search field. - Click Run_FetchFAZEvents.
- Deselect Agile and select it again to resume the updates.
Others
To view log message errors, go to ServiceNow, click All applications and search for Organisation Log. Then select Application Logs.
In the App Log pane, check for errors. You lot tin can filter by keywords to search for messages.
Fault | Possible solutions |
---|---|
User cannot log in |
|
Error message: | Cheque the name and spelling of the Domain. |
Error message: | Assign the x_forti_fazintgv2.snAPI office to the ServiceNow account. Encounter Setting upward the FortiAnalyzer Integration App. |
Fault bulletin: | Assign the import_transformer to the ServiceNow account. See Setting up the FortiAnalyzer Integration App. |
FortiAnalyzer Incidents are not up-to-date | Synchronizing incidents takes time. Expect a few minutes and attempt once more. |
Source: https://docs.fortinet.com/document/fortianalyzer/6.2.3/servicenow-integration-2-0-user-guide/961240/troubleshooting
Posted by: orvisbrimee.blogspot.com
I really liked your blog post.Much thanks again. Awesome.
ReplyDeleteServiceNow Online Training in Hyderabad
ServiceNow Course Online