Technical Tip: Using FortiAnalyzer event handler and FortiGate automation stitch to trigger a failover
| Description | This article describes how to use FortiAnalyzer Event Handler with FortiGate automation stitch to trigger FortiGate cluster failover. |
| Scope | FortiAnalyzer, FortiGate. |
| Solution | Note: In this example, the Event Handler will be configured to be triggered when the FortiGate CPU value exceeds 5% for testing purposes; this can be changed accordingly.
In FortiAnalyzer, create a new handler for high CPU (ensure the automation stitch option is enabled). Event Handler can be created by going under Incidents & Events -> Event Handlers -> Event Handlers, and select 'Create New'.
An example of the handler is shown below:
An example of the rule is shown below:
On the FortiGate side, configure the automation stitch by navigating to Security Fabric -> Automation. Choose the trigger as FortiAnalyzer Event Handler and choose the previously created handler as shown below:
Configure the Action for failover as shown below:
Configure the automation stitch as shown below:
If the CPU in the FortiGate reaches 5% or more, the Event Handler in FortiAnalyzer will trigger, which will then trigger the failover automation stitch in the FortiGate.
This can also be configured alternatively, using FortiAnalyzer Playbooks. Refer to Technical Tip: FortiGate HA failover using FortiAnalyzer automation.
Make sure that the FortiAnalyzer's certificate is authorized in FortiGate. It is necessary for the OFTP communication between the FortiGate and FortiAnalyzer for the stitch to be triggered on the firewall. |





