Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
baker_gt
New Contributor

Event Handlers with suppression.

Hi guys,

 

We have 40 units all reporting back to our FAZ. Most sites have 2x internet connections in SD-Wan.

 

Problem is we don't know if a primary link fails, and the client is running from 4G.

 

We have handlers setup to alert on interface up and down and route added  / removed.

 

 

SD-Wan we have by looking in event logs, and the generic text filter of    msg ~ "Static route is added"  

 

But we could get 2-3 of these in 5 min about the same thing.

 

 

I would LOVE a way to get FAZ to hold the alert for 5 min, to see if there is a matching up or down event.

 

 

One morning we walked in to 300 emails about ups and downs. It means we can miss one that didnt come back right when another site was flapping.

2 REPLIES 2
abelio
SuperUser
SuperUser

Hi,

just adjust  your handler's "sensivity" in order to match your needs

 

 

regards




/ Abel

regards / Abel
baker_gt

Sorry, i see how to do that, unless you mean 

 

Generate alert when at least  matches occurred over a period of  minutes

 

 

Labels
Top Kudoed Authors