FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
haziqsulaiman
Article Id 422795
Description

This article describes how to use FortiAnalyzer Event Handler with FortiGate Automation Stitch to trigger FortiGate cluster failover.

Scope FortiAnalyzer, FortiGate.
Solution

Note:

In this example, the Event Handler will be configured to be triggered when the FortiGate CPU value exceeds 5% for testing purposes; this can be changed accordingly.

 

In FortiAnalyzer, create a new handler for high CPU (ensure the Automation Stitch option is enabled). Event Handler can be created by going under Incidents & Events -> Event Handlers -> Event Handlers, and select 'Create New'.

 

An example of the handler is shown below:

 

handler.png

 

An example of the rule is shown below:

 

2. rule.png

 

On the FortiGate side, configure the Automation Stitch by going under Security Fabric -> Automation. Choose the trigger as FortiAnalyzer Event Handler and choose the previously created handler as shown below:

 

3. trigger.png

 

Configure the Action for failover as shown below:

 

4. action.png

 

Configure the Automation Stitch as shown below:

 

5. stitch.png

 

If the CPU in the FortiGate reaches 5% or more, the Event Handler in FortiAnalyzer will trigger, which will then trigger the failover Automation Stitch in the FortiGate.

 

This can also be configured alternatively, using FortiAnalyzer Playbooks. Refer to the following KB article: Technical Tip: FortiGate HA failover using FortiAnalyzer automation