Predefined event handlers
FortiAnalyzer includes many predefined event handlers that you can use to generate events. You can easily create a custom event handler by cloning a predefined event handler and customizing its settings. See Cloning event handlers.
In 6.2.0 and up, predefined event handlers have been consolidated and have multiple filters that can be enabled or disabled individually.
The following are a small sample of FortiAnalyzer predefined event handlers. To see all predefined event handlers, go to Incidents & Events > Event Monitor > Event Handler List and select Show Predefined.
Event Handler |
Description |
---|---|
Default-Compromised Host-Detection-by IOC-By-Threat |
Disabled by default Filter 1:
Filter 2:
Filter 3:
|
Default-Data-Leak-Detection-By-Threat |
Disabled by deafult Filter 1:
Filter 2:
|
Default-Sandbox-Detections-By-Endpoint |
Disabled by default Filter 1:
Filter 2:
Filter 3:
|
Local Device Event |
Available only in the Root ADOM. Enabled by default
|
FortiOS system events
FortiOS predefined system event handlers are consolidated into a single event handler with multiple filters called Default FOS System Events.
Events are organized by device in the Incidents & Events dashboards, which can be expanded to view all related events.
Default FOS System Event filters apply tags to each event, allowing you to identify which Deafult FOS System Event filter triggered the event.
If you are upgrading from a version before FortiAnalyzer 6.2.0, the existing legacy predefined handlers which are enabled or have been modified will be available as custom handlers. In the Event Handler List, select the More dropdown and choose Show Custom. |