Event Handler configuration is improved to support more values for 'Group by' and to setup custom Event Type, Event Status and Indicators.
- Go to FortiSoC > Handlers > Event Handler List, and click Create New.
FortiAnalyzer event handlers now support up to three GroupBy values in the filter settings.
In the Event Monitor, users can enable the Group By, Group By 2, and Group By 3 columns or filter by these groups.
FortiAnalyzer event handlers support customized event statuses and event types. Users can manually enter in a custom event status or type, or leave the field blank to use the default values.
Customized event types and event statuses can be viewed from the Event Monitor.
FortiAnalyzer event handlers include the Indicators field. Indicators keep track of distinct values for certain log fields chosen by the user. Each filter allows for up to five indicators, and each indicator can store up to 10 values.
A new clickable Indicators column is available in the Event Monitor. When a user clicks on an indicator, a dialog window appears to display the details of the indicators including their name, type, and values.
When an incident is raised from an event which includes the indicators field, you can view indicator details in the Indicators tab under the incident timeline.