2.1.12 Ensure single CPU core overloaded event is logged

Information

Add log-single-cpu-high option under config system global. When enabled, CPU single core usage will be polled every three seconds, and any single CPU core usage above the CPU usage threshold will report an event log. If a core is reported, that core will not be checked again for the next 30 seconds.

There are instances where overall CPU usage is low, but there is a single CPU core that is overloaded. But because reporting and dashboard in FortiGate shows the overall CPU usage, a single CPU core spike may get overlooked on a FortiGate with multiple CPU cores. This causes performance issues where there are instances which traffic has been stopped processing.

Solution

On CLI:

config system global
set log-single-cpu-high enable
end

See Also

https://workbench.cisecurity.org/benchmarks/15284

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2, 800-53|AU-3, 800-53|AU-3(1), 800-53|AU-7, 800-53|AU-12

Plugin: FortiGate

Control ID: 6956f587d0f6814dba972f2f0af672a0c7e296d3793fc74d285e9e258647d7c7