FortiSIEMcollectorsare responsible forgathering logsfrom devices andforwarding themto the FortiSIEM cluster. Their communication with the cluster follows these key principles:
●Collectors periodically communicate with the supervisor node.
● This allows them toreport status, receive updates, and verify configurations.
●The supervisor periodically checks the health of the collector.
● Thesupervisor monitors the collector’s uptime, connectivity, and performance.
●Collectors upload event data to worker nodes but report health to the supervisor.
●Event logs are uploaded to worker nodesas per theworker upload list, ensuring distributed event processing.
●Health status is always reported directly to the supervisorfor centralized monitoring.