Skip to content

[11.2.14] Federation Services connectivity failure and tenant alerts not loading #2772

Description

@Andrei-R-HancoGlobal

Acknowledgements

Describe the bug

Two issues are affecting SOC monitoring and alert management in UTMStack 11.2.14-enterprise, both still present on 29 September 2026:

  1. Federation Services is no longer communicating correctly with connected client instances, preventing normal monitoring through the central panel.
  2. One affected tenant cannot display its alerts, even when accessed directly through its individual URL. Alert counters and filter summaries populate, but the alert table fails to load.

Direct tenant access works for some other instances and provides a partial workaround for the Federation Services issue.

Client names and tenant URLs are withheld for confidentiality.

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

Federation Services should communicate with connected client instances and allow normal monitoring and alert management.

The tenant alert table should display the records matching the selected time range and status, consistently with the displayed counters and filter summaries.

Current Behavior

Federation Services is failing to communicate correctly with connected client instances.

On one affected tenant, direct access also fails to load the alert list under Threat Management → Manage Alert. The table displays "No data found" and the following error appears:

An error occurred while listing the alerts. Please try again later.

We captured these results in separate screenshots:

Selected period Total alerts Open In review Completed Alert table
Last 7 days 1,913 1,080 6 827 No data found
Last 12 hours 1,089 1,089 0 0 No data found
Last 15 minutes 5 5 0 0 No data found
Image Image

The counters and filter summaries change with the selected period, indicating that some data remains available while individual alert records cannot be displayed.

The 1,089 open alerts are counted within the last-12-hours filter. Reducing the range to the last 15 minutes returns only five matching alerts, but the listing still fails.

This demonstrates that the failure also affects small result sets and should not be attributed solely to a large accumulated alert backlog. The loading failure itself prevents us from reviewing and managing these alerts.

Last 12 hours

Last 12 hours: 1,089 alerts counted but no records displayed

Last 15 minutes

Last 15 minutes: five alerts counted but the list still fails

Reproduction Steps

Federation Services issue:

  1. Open the central Federation Services panel.
  2. Attempt to access and monitor connected client instances.
  3. Observe that communication/access through the federated panel is not working correctly.

Tenant alert-listing issue:

  1. Access the affected tenant directly through its individual URL.
  2. Navigate to Threat Management → Manage Alert.
  3. Select All statuses and the last 12 hours.
  4. Observe populated alert counters and filter summaries, while the table displays "No data found."
  5. Change the time range to the last 15 minutes.
  6. Observe that the counters update, but the alert list still fails and displays the alert-listing error.

At the time of testing, the last-15-minutes selection contained only five alerts.

Possible Solution

No confirmed fix or root cause is available.

Please investigate the Federation Services communication failure and compare the requests that populate alert counters/filter summaries with the request that retrieves the alert list.

Please also confirm whether either issue is related to the deployment of version 11.2.14 and provide a workaround and estimated resolution time.

Additional Information/Context

Centralised monitoring is disrupted, requiring technicians to check client instances individually. For the affected tenant, direct access does not resolve the alert-listing failure, preventing investigation, triage, and status updates.

The screenshots show that counters respond to recent time-range selections. They do not independently establish ingestion timestamps or confirm that all backend services are healthy.

We noticed that the affected instance is running version 11.2.14-enterprise and suspect recent downtime may have coincided with an upgrade or maintenance activity. This connection is not confirmed.

Our SOC was not aware of an announced maintenance window. Please confirm whether maintenance occurred, its timing, and any relationship to these issues.

We have previously requested advance notification of maintenance affecting availability. Please ensure future maintenance windows are communicated beforehand so we can plan monitoring coverage.

UTMStack Version

v11.2.14-enterprise

Operating System and version

v11.2.14-enterprise

Hypervisor and Version | Server Vendor and Model

N/A

Browser and version

Brave/Chome/Edge on latest versions prior to 29.09.2026

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions