FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
haziqsulaiman
Article Id 420295
Description This article describes how to create an event handler in FortiAnalyzer to detect failed admin login from FortiGate.
Scope FortiAnalyzer.
Solution

In FortiAnalyzer, go to Incidents & Events -> Event Handlers -> Event Handlers, and select Create New and enter a new name for the handler:

 

1. newhandler.png

 

Under the Rules section, select Add New Rule and set as the following configurations:

Log Device Type: FortiGate.

Log Type: Event Log (event).

Log Subtype: System (system).

Log Field: Device ID (devid). This is only used for categorizing the events and can be changed as per requirements

Log Filters: Log Description Equal To Admin login failed.

 

The following is an example of the rule configuration:

 

2. newrule.png

 

The event generated can be seen from Incidents & Events -> All Events. An example is shown below:

 

3. test.png