Technical Tip: How create an Event Handler in FortiAnalyzer when a SSL VPN login fail event is detected on FortiGate side
| Description | This article describes how to create an event handler in FortiAnalyzer for an SSL VPN login that failed in FortiGate. |
| Scope | FortiAnalyzer v7.0.10 and later, v7.2.0 and later, v7.4.0 and later. |
| Solution | Login to FortiAnalyzer and under FortiSoc -> Handlers -> FortiGate Event Handlers, select 'Create New'.
On Devices tab, specify the device name or apply the handler to all FortiGates
Define when the alert will be generated. In this case, when at least two exact events occur over a period of 1 minute, the alert will be generated. Additionally, it is possible to set a severity for the event and some Tags.
Test:
To see how the event handler is executed, run the debug before testing the SSL VPN connection:
Under FortiSoc -> Handlers -> FortiGate Event Handlers list, it is possible to see in the 'Events' column how the count is increasing every time the handler is triggered.
Related Article: |




