Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The following issues have been fixed in FortiEDR 7.2.3. For inquires about a particular bug, please contact Customer Service & Support.

Central Manager - Build 7.2.3.0103

Bug ID Description
1261397 The AV signature policy feature is disabled after upgrade.
1261405 Uploading an older AV signature file can be incorrectly marked as the latest version.
1262005 Newly added applications in Application Control are set to Enabled instead of Disabled by default.
1266943 Switching organizations while secure browser events are displayed can cause an error if the target organization does not have secure browser enabled.
1261402, 1261396

New Collector groups are not automatically assigned to the default AV signature policy or Collector settings policy when no other AV signature policy or Collector settings policy exists.

1261407

Disable the Workloads feature by default.

1264448

UI issue where some tables are slightly cut off at the bottom.

1266944

Secure browser URL reputation data can display an empty category.

1266945

Secure browser events do not display due to an underlying communication issue.

1268176

A specific consolidation failed in lab.

1266364

Hide the build number in the footer tooltip for non-support users.

1262649, 1256967

Infrastructure related to a future feature (post detection flow).

Central Manager - GA Build (7.2.3.0085)

Bug ID Description
1174797, 1177824

Threat Hunting query that contains "NOT" does not filter correctly.

1230971, 1231450

Parsing failure of Taxii feed.

1243237, 1245594

No audit log for in disabling SAML authentication.

1257703, 1249534, 1258256

Adding a process to Exclusion Policy via Incident View results in blank screen.

1229966, 1230923

Exception creation fails due to an empty value.

1234632, 1234818

Failure in retrieving reports from a disconnected Collector.

1222844, 1224855

list-exceptions Rest API function does not display selected Collector groups.

1224830, 1224852

Users with a Read-Only role cannot export data from the Inventory page.

1217600, 1224858

Hardening related to key injection as a variable.

1229820, 1233765

Issue with dashboard queries of "Top Affected Devices".

1234348, 1239292

Incident Report fails to display the full event process path.

1231073, 1235251

Incident report generation gets stuck at 5%.

1214941, 1215757

count-events REST API function returns inaccurate results when filtering by IP address.

1231674, 1232143

Classification response actions are displayed in the wrong chronological order in Incident View.

1219174, 1220532

"Collectors By Policy" widget export does not match the widget display.

1234440, 1240548, 1237245

Syslog becomes unresponsive due to a status update failure, causing log transmission to stop unexpectedly.

1230144, 1235745

Exception is created on the wrong security event.

1219162, 1231830

Widgets cannot be selected on the Dashboard page.

1233707, 1234310

Adding an incident comment is logged with a default user information.

1232273, 1233766

Sorting by total number does not correctly order the values in Incident View.

1217982, 1222702

Wrong file or process name is displayed while the correct file has been remediated.

1227989, 1250027, 1228723

Applying the “Malicious” classification filter prevents associated raw events from being displayed.

1252095, 1252561

Applying a filter prevents exporting the Collectors report in the Inventory.

1252094, 1226670, 1252560

Incidents sometimes appear as unclickable duplicates when you scroll or hover in the UI.

1251352

Certain events are partially saved during consolidation.

1254115, 1252688, 1250220

Editing an exception incorrectly displays an event as "deleted".

1244654, 1246159, 1244724, 1244129, 1246479

Potential error in consolidation flow.

1243125, 1251355

Multiple entities are marked as erased but are not actually cleaned from the database.

1230520, 1240181

When creating an exception via handling an event, selecting an IP from the destination list incorrectly selects all IPs.

1221298, 1231457

Deleting an organization or changing license capacity does not save the changes or causes the environment to hang.

1236064, 1238202

Raw Data Items cannot be retrieved from Event ID using Rest API.

1240953, 1245595, 1242029

Deleting an event while using a filter results in deletion of multiple events within the same aggregation.

1225502, 1247886, 1246187, 1240786, 1235482, 1231053

Updating the license blocks Collector registrations.

1227194, 1243039, 1227652

Changing an exception’s destination from "Specific" to "All Destinations" incorrectly triggers a “cannot select both” error.

1234354, 1235517, 1245708, 1237735

Performance issue with event processing.

1250351, 1251431

Security Policy Search fails due to an internal error.

1248720, 1249641

Error when creating an exception on a specific event.

1224946, 1242028

SMTP is active only on Hoster.

1243641, 1244635

Issue with exporting unmanaged devices list.

1252134, 1254404

Click "Add Connector" and the dropdown shows most connector options grayed out.

1239170, 1246197

LDAP error when choosing SSL or TLS.

1111981, 1218423

When syslog field values are too long, the first max characters will be displayed.

1223419, 1235747

No audit log when a user modifies their own user advanced settings.

1220303, 1221131

Export-iot-json return java exception instead of a meaningful error message.

Refer to What's new for a list of new features, enhancements, and changes. Refer to Known issues for a list of known issues.

Resolved issues

Resolved issues

The following issues have been fixed in FortiEDR 7.2.3. For inquires about a particular bug, please contact Customer Service & Support.

Central Manager - Build 7.2.3.0103

Bug ID Description
1261397 The AV signature policy feature is disabled after upgrade.
1261405 Uploading an older AV signature file can be incorrectly marked as the latest version.
1262005 Newly added applications in Application Control are set to Enabled instead of Disabled by default.
1266943 Switching organizations while secure browser events are displayed can cause an error if the target organization does not have secure browser enabled.
1261402, 1261396

New Collector groups are not automatically assigned to the default AV signature policy or Collector settings policy when no other AV signature policy or Collector settings policy exists.

1261407

Disable the Workloads feature by default.

1264448

UI issue where some tables are slightly cut off at the bottom.

1266944

Secure browser URL reputation data can display an empty category.

1266945

Secure browser events do not display due to an underlying communication issue.

1268176

A specific consolidation failed in lab.

1266364

Hide the build number in the footer tooltip for non-support users.

1262649, 1256967

Infrastructure related to a future feature (post detection flow).

Central Manager - GA Build (7.2.3.0085)

Bug ID Description
1174797, 1177824

Threat Hunting query that contains "NOT" does not filter correctly.

1230971, 1231450

Parsing failure of Taxii feed.

1243237, 1245594

No audit log for in disabling SAML authentication.

1257703, 1249534, 1258256

Adding a process to Exclusion Policy via Incident View results in blank screen.

1229966, 1230923

Exception creation fails due to an empty value.

1234632, 1234818

Failure in retrieving reports from a disconnected Collector.

1222844, 1224855

list-exceptions Rest API function does not display selected Collector groups.

1224830, 1224852

Users with a Read-Only role cannot export data from the Inventory page.

1217600, 1224858

Hardening related to key injection as a variable.

1229820, 1233765

Issue with dashboard queries of "Top Affected Devices".

1234348, 1239292

Incident Report fails to display the full event process path.

1231073, 1235251

Incident report generation gets stuck at 5%.

1214941, 1215757

count-events REST API function returns inaccurate results when filtering by IP address.

1231674, 1232143

Classification response actions are displayed in the wrong chronological order in Incident View.

1219174, 1220532

"Collectors By Policy" widget export does not match the widget display.

1234440, 1240548, 1237245

Syslog becomes unresponsive due to a status update failure, causing log transmission to stop unexpectedly.

1230144, 1235745

Exception is created on the wrong security event.

1219162, 1231830

Widgets cannot be selected on the Dashboard page.

1233707, 1234310

Adding an incident comment is logged with a default user information.

1232273, 1233766

Sorting by total number does not correctly order the values in Incident View.

1217982, 1222702

Wrong file or process name is displayed while the correct file has been remediated.

1227989, 1250027, 1228723

Applying the “Malicious” classification filter prevents associated raw events from being displayed.

1252095, 1252561

Applying a filter prevents exporting the Collectors report in the Inventory.

1252094, 1226670, 1252560

Incidents sometimes appear as unclickable duplicates when you scroll or hover in the UI.

1251352

Certain events are partially saved during consolidation.

1254115, 1252688, 1250220

Editing an exception incorrectly displays an event as "deleted".

1244654, 1246159, 1244724, 1244129, 1246479

Potential error in consolidation flow.

1243125, 1251355

Multiple entities are marked as erased but are not actually cleaned from the database.

1230520, 1240181

When creating an exception via handling an event, selecting an IP from the destination list incorrectly selects all IPs.

1221298, 1231457

Deleting an organization or changing license capacity does not save the changes or causes the environment to hang.

1236064, 1238202

Raw Data Items cannot be retrieved from Event ID using Rest API.

1240953, 1245595, 1242029

Deleting an event while using a filter results in deletion of multiple events within the same aggregation.

1225502, 1247886, 1246187, 1240786, 1235482, 1231053

Updating the license blocks Collector registrations.

1227194, 1243039, 1227652

Changing an exception’s destination from "Specific" to "All Destinations" incorrectly triggers a “cannot select both” error.

1234354, 1235517, 1245708, 1237735

Performance issue with event processing.

1250351, 1251431

Security Policy Search fails due to an internal error.

1248720, 1249641

Error when creating an exception on a specific event.

1224946, 1242028

SMTP is active only on Hoster.

1243641, 1244635

Issue with exporting unmanaged devices list.

1252134, 1254404

Click "Add Connector" and the dropdown shows most connector options grayed out.

1239170, 1246197

LDAP error when choosing SSL or TLS.

1111981, 1218423

When syslog field values are too long, the first max characters will be displayed.

1223419, 1235747

No audit log when a user modifies their own user advanced settings.

1220303, 1221131

Export-iot-json return java exception instead of a meaningful error message.

Refer to What's new for a list of new features, enhancements, and changes. Refer to Known issues for a list of known issues.