FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
Pedro_FTNT
Staff
Staff
Article Id 307623
Description This article describes how to configure Event Handler Alerts to JITTER SD-WAN.
Scope FortiAnalyzer, FortiSoC, SD-WAN, Event Handler.
Solution

To configure Handler:

  1. Go to FortiAnalyzer -> FortiSoC -> Handlers -> Data Selector List and select 'Create New'.

 

2.png

 

  • Set Name.
  • Select Device or Devices.

 

8.png

 

7.png

 

  1. Go to FortiSoC -> Handlers -> Notification Profile List and select 'Create New'.

 

3.png

 

  • Complete data.
  • To configure the Mail Server refer: Mail Server

 

9.png

 10.png

 

  1. Go to FortiSoC -> Handlers -> Event Handler List and select 'Create New'.

 

5.png

 

  • Select Status Enable.
  • Set Name.
  • Select Data Selector.
  • Configure Rules.
  • Set Notifications profile.

 

11.png

 

  1. Rules Configuration to SDWAN JITTER: fail and recovery sequence.
  • Service prioritized by performance.

metric="jitter" and msg='Service prioritized by performance metric will be redirected in sequence order'.

 

12.png

 

  • Stop forwarding traffic.

 

subtype=="sdwan" AND metric=="jitter" AND msg~"Stop forwarding traffic."

 

13.png

 

  • Start forwarding traffic.

 

subtype=="sdwan" AND metric=="jitter" AND msg~"Start forwarding traffic."

 

14.png

 

  1. Mail Alerts received:
  • Start forwarding traffic.

 

15.png

 

  • Service prioritized by performance.

 

16.png

 

  • Stop forwarding traffic.

 

17.png

 

Related articles:

Contributors