Description | This article describes how to create an event handler in FortiAnalyzer for an SSL VPN login that failed in FortiGate. |
Scope |
FortiAnalyzer v7.0.10 and later, v7.2.0 and later, v7.4.0 and later. |
Solution |
Login to FortiAnalyzer and under FortiSoc -> Handlers -> FortiGate Event Handlers, select 'Create New'.
On Devices tab, specify the device name or apply the handler to all FortiGates
Define when the alert will be generated. In this case, when at least two exact events occur over a period of 1 minute, the alert will be generated. Additionally, it is possible to set a severity for the event and some Tags.
Test:
To see how the event handler is executed, run the debug before testing the SSL VPN connection:
Under FortiSoc -> Handlers -> FortiGate Event Handlers list, it is possible to see in the 'Events' column how the count is increasing every time the handler is triggered.
Related Article:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.