Event Handler
Go to Analytics > Incidents & Events > Event Handler, to view event handlers and create notification profiles for events.
This topic contains the following information:
To view event handlers:
-
Go to Analytics > Incidents & Events > Event Handler. The list of event handlers is displayed.
-
Hover the mouse over each event handler to display a tooltip of information.
Creating Event Handlers
To create an Event Handler:
- Go to Analytics > Incidents & Events > Event Handler.
- In the Event Handler tab, click Create.
- Configure the Event Handler details:
Field
Description
Name Enter the event handler name. Event Type Select and event type from the dropdown. Description (Optional) Enter a description of the event handler. - Configure the event Rules.
- Click Create.
- (Optional) Toggle Status to enable/disable the event handler.
- Select the event Severity from the dropdown.
Choose Your Logs: Select the Log Type and Log Subtype that you want to monitor for events. Select the Log Field to categorize logs into smaller groups based on the chosen log fields.
Refine Your Logs: Once logs are grouped, you can refine the data within each group by applying filters with other log fields. Logs that match the filters will be retained within each group.
Define Event Conditions: Once you have organized and filtered the logs, set up criteria that enables the system to automatically initiate events when log records reoccur within each group.
- Click OK.
To clone an Event Handler:
- Go to Analytics > Incidents & Events > Event Handler.
- Select a handler from the list and click Clone.
- Edit the Event Handler Details and Rules and click OK.
Creating Notification Profiles
To create a notification profile:
- Go to Analytics > Incidents & Events > Event Handler.
- On the Notification Profile tab, click Create New.
- Enter a name for the profile.
- If desired, enable Email.
- Configure the desired email addresses to send the notification to.
- Configure the Subject field as desired, then click OK.
- If desired, enable Webhook.
- Configure the webhook options as follows:
Field
Description
Type
Select Generic or MS Teams.
Port
Available if you selected Generic. Enter the port number that FortiGate Cloud uses to communicate with the platform.
Method
Select POST or PUT for the REST API call method.
Title
Enter the title for the message.
URL
Enter the webhook URL from the desired platform.
HTTP body
Available if you selected Generic. Enter the message body text.
HTTP authentication
Available if you selected Generic.
Select Basic or OAuth2 to configure and allow HTTP authentication between FortiGate Cloud and the platform.
Username
Available if you selected Basic for HTTP authentication. Enter the username to use for HTTP authentication between FortiGate Cloud and the platform.
Password
Available if you selected Basic for HTTP authentication. Enter the password to use for HTTP authentication between FortiGate Cloud and the platform.
Authorization server
Available if you selected OAuth2 for HTTP authentication. Enter the IP address of the authorization server to use for HTTP authentication between FortiGate Cloud and the platform.
Auth client ID
Available if you selected OAuth2 for HTTP authentication. Enter the client ID to use for HTTP authentication between FortiGate Cloud and the platform.
Auth client secret
Available if you selected OAuth2 for HTTP authentication. Enter the client secret to use for HTTP authentication between FortiGate Cloud and the platform.
- Click OK.
- Configure the webhook options as follows:
Creating Incidents
When an automation stitch is triggered, a new event is created in the Event Monitor. You can use this event to create or update an incident, allowing repeated triggers to be tracked against the same incident.
To create an incident:
- Go to Incidents & Events > Event Monitor.
- Select an event and click Actions > Create New Incident. The Create New Incident pane opens. Alternatively, you can select Add to Existing Incident and select an incident from the list.
- Configure the incident and click OK. The incident is added to the Incidents page.
Field Description Name Enter a descriptive name for the incident to identify the issue. Incident Category Select the incident category from the dropdown. Severity Select the severity level of the incident. Status Selec the current state of the incident. Description Provides additional details about the incident. Enter relevant context or observations to support investigation. Assign To Assign a user to manage the incident.