Fortinet white logo
Fortinet white logo

User Guide

Event Categories and Handling

FortiSIEM Event Categories and Handling

This topic provides a brief description of various types of event categories in FortiSIEM.

System Event
Category
Description Counted in
EPS License
phstatus -a
outout
Stored in DB?
0 External events and not flow events (e.g. syslog, SNMP Trap, Event pulling) Yes EPS Yes
1 Incidents (events that begin with PH_RULE) No EPS INTERNAL Yes
2 FortiSIEM Audit Events (events that begin with PH_AUDIT) No EPS INTERNAL Yes
3 FortiSIEM Internal system logs, free format No EPS INTERNAL Yes
4 External flow events (Netflow, Sflow) Yes EPS Yes
5 FortiSIEM Internal health events for summary dashboards No EPS INTERNAL Yes
6 FortiSIEM Performance Monitoring events (events that begin with PH_DEV_MON) Yes EPS PERF Yes
7 AO Beaconing events No EPS INTERNAL Yes
8 FortiSIEM Real Time Performance Probe Events No EPS INTERNAL No
99 FortiSIEM Internal Rule Engine No EPS INTERNAL No

Event Categories and Handling

FortiSIEM Event Categories and Handling

This topic provides a brief description of various types of event categories in FortiSIEM.

System Event
Category
Description Counted in
EPS License
phstatus -a
outout
Stored in DB?
0 External events and not flow events (e.g. syslog, SNMP Trap, Event pulling) Yes EPS Yes
1 Incidents (events that begin with PH_RULE) No EPS INTERNAL Yes
2 FortiSIEM Audit Events (events that begin with PH_AUDIT) No EPS INTERNAL Yes
3 FortiSIEM Internal system logs, free format No EPS INTERNAL Yes
4 External flow events (Netflow, Sflow) Yes EPS Yes
5 FortiSIEM Internal health events for summary dashboards No EPS INTERNAL Yes
6 FortiSIEM Performance Monitoring events (events that begin with PH_DEV_MON) Yes EPS PERF Yes
7 AO Beaconing events No EPS INTERNAL Yes
8 FortiSIEM Real Time Performance Probe Events No EPS INTERNAL No
99 FortiSIEM Internal Rule Engine No EPS INTERNAL No