Skip to main content
holdenk
New Member
March 21, 2019
Question

Difference between FortiGate Event Handlers and Event Handlers List in Mo

  • March 21, 2019
  • 2 replies
  • 6545 views

Hello,

 

Would anybody be able to tell me what the differences are between the "Event Handler List" and "FortiGate Event Handlers" in FortiAnalyzer/FortiManager?  The documentation is very vague on FortiGate Event Handlers.  Adding a FortiGate Event Handler doesn't seem to do anything.  The Event Handler List works as expected.

 

2 replies

brazz_FTNT
Staff
Staff
March 21, 2019

FortiGate event handlers All FortiGates added to FortiAnalyzer use a default event handler on the FortiAnalyzer side to receive high severity events such as Botnet Communication, IPS Attack Pass Through, and Virus Pass Through AntiVirus. You can create custom FortiGate event handlers. The triggered event from FortiGate Event Handler is not shown in the FortiAnalyzer GUI. The events are pushed to the FortiGate for further processing.

chutter_FTNT
Staff
Staff
March 22, 2019

Hello,

 

the FGT Event Handlers are for FortiOS automation only.

Whenever the FAZ has a match in the FGT Event Handler it informs the FGT about it and depending on the configuration of the FGT the FGT takes action. (Quarantine, IP BAN .....)

The FGT Events triggered by the FGT Event Handlers are not displayed in the FAZ Event Manager.

 

Regards

Christian

holdenk
holdenkAuthor
New Member
March 22, 2019

I am unable to get this to work.  Do you know of any resources that talk about this?  The documentation is very vague

chall_FTNT
Staff
Staff
March 28, 2019

holdenk,

It would be best to open a support ticket.