Created on
10-31-2024
03:32 AM
Edited on
06-22-2025
11:17 PM
By
Jean-Philippe_P
Description | This article describes the FortiAnalyzer Event Handler to detect Data Exfiltration. |
Scope | FortiAnalyzer v7.2.0 and above. |
Solution |
Starting from FortiAnalyzer version 7.2.0, a Data Exfiltration detection feature has been added. It can be configured as a Basic Handler or Correlation Handler using the aggregation expression SUM.
An aggregation field can be used for log fields such as duration, sentbyte, rcvdbyte, sentpkt, and rcvpkt.
The following example shows a Basic Event Handler that will trigger an Alert when a minimum threshold of sentbytes is met during a specific duration.
Note: The Aggregation expression SUM will work only if :
If the SIEM Module is enabled can be verified via the:
config system global (global)# set disable-module
The SIEM Module should not be listed as a 'disable-module'.
Related documents: Creating a custom event handler Technical Tip: FortiAnalyzer Event Handler for data exfiltration detection Troubleshooting Tip: How to troubleshoot for event handler related issues Technical Tip: Event handler triggered on sent or received bytes from specific IP address |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.