Created on
05-16-2025
04:06 AM
Edited on
06-22-2025
11:09 PM
By
Jean-Philippe_P
This article describes how to set up an event handler triggered by a specific size of sent or received bytes.
FortiAnalyzer.
Note: 10 KB is used just for testing here. In a real environment, the actual value should be based on what is required.
Possible options include Kilo Bytes, Mega Bytes, Giga Bytes, and Terra Bytes.
triggername="sum" AND handler_type="basic"
Note:
By using the 'Creating notification profiles', this information can be provided to the team in real time.
SUM option will work only if :
If the SIEM Module is enabled can be verified via the:
config system global
(global)# set disable-module
fortiview-noc FortiView/NOC-SOC module.
siem SIEM module.
soc SOC module.
ot-view OT-VIEW module.
none No modules disabled.
The SIEM Module should not be listed as a 'disable-module'.
Related documents:
Creating a custom event handler
Technical Tip: FortiAnalyzer Event Handler for data exfiltration detection
Troubleshooting Tip: How to troubleshoot for event handler related issues
Technical Tip: FortiAnalyzer Event Handler for data exfiltration detection
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.