Hi,
I went through built-in event handlers in FAZ and found some windows privilege escalation handlers. Could I use them with Windows Servers without Forticlient installed? If so, is there any cookbook or docs how to set it up?
Thanks
Robert
Solved! Go to Solution.
Since event handler alerts are triggered based on the rules set. Depending on which exact type of event handlers, if the event handler rule trigger is based a certain log device type, it will require the exact logs from the specified device.
As per below sample, the log device type is for FortiClient. Hence, only FortiClient device type of logs will be able to trigger the event handler alerts.
Since event handler alerts are triggered based on the rules set. Depending on which exact type of event handlers, if the event handler rule trigger is based a certain log device type, it will require the exact logs from the specified device.
As per below sample, the log device type is for FortiClient. Hence, only FortiClient device type of logs will be able to trigger the event handler alerts.
User | Count |
---|---|
2035 | |
1164 | |
770 | |
448 | |
327 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.