FortiProxy event log trigger
You can configure a FortiProxy event log trigger for when a specific event log ID occurs. You can select multiple event log IDs, and apply log field filters.
To configure a FortiProxy event log trigger in the GUI:
-
Go to Security Fabric > Automation, select the Trigger tab, and click Create New.
-
In the Miscellaneous section, click FortiProxy Event Log.
-
Enter a name and description.
-
In the Event field, click the + to select multiple event log IDs.
The Event options correspond to the Message Meaning listed in the Log Message Reference. Hover over an entry to view the tooltip that includes the event ID and log name. In this example, the Admin login successful event in the GUI corresponds to log ID 32001, which is LOG_ID_ADMIN_LOGIN_SUCC.
-
In the Field filter(s) field, click the + to add multiple field filters. The configured filters much match in order for the stitch to be triggered.
-
Click OK.
To configure a FortiProxy event log trigger in the CLI:
config system automation-trigger edit "event_login_logout" set description "trigger for login logout event" set event-type event-log set logid 32001 32003 config fields edit 1 set name "user" set value "csf" next edit 2 set name "srcip" set value "10.6.30.254" next end next end