Hello,
Would anybody be able to tell me what the differences are between the "Event Handler List" and "FortiGate Event Handlers" in FortiAnalyzer/FortiManager? The documentation is very vague on FortiGate Event Handlers. Adding a FortiGate Event Handler doesn't seem to do anything. The Event Handler List works as expected.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
FortiGate event handlers All FortiGates added to FortiAnalyzer use a default event handler on the FortiAnalyzer side to receive high severity events such as Botnet Communication, IPS Attack Pass Through, and Virus Pass Through AntiVirus. You can create custom FortiGate event handlers. The triggered event from FortiGate Event Handler is not shown in the FortiAnalyzer GUI. The events are pushed to the FortiGate for further processing.
Hello,
the FGT Event Handlers are for FortiOS automation only.
Whenever the FAZ has a match in the FGT Event Handler it informs the FGT about it and depending on the configuration of the FGT the FGT takes action. (Quarantine, IP BAN .....)
The FGT Events triggered by the FGT Event Handlers are not displayed in the FAZ Event Manager.
Regards
Christian
I am unable to get this to work. Do you know of any resources that talk about this? The documentation is very vague
holdenk,
It would be best to open a support ticket.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.