Working with Event Types
After parsing an event or log, FortiSIEM assigns a unique event type to that event/log. When you create a new custom parser for device logs, you have to add a new event type to FortiSIEM so the log events can be identified.
This section provides the procedure to create event types.
Adding an Event Type
Complete these steps to add an event:
- Go to ADMIN > Device Support> Event Types tab.
- Click New.
- In the Event Definition dialog box, enter the information below.
Settings Guidelines Name [Required] If the event will be used for Custom Monitoring, the Event Type name must begin with PH_DEV_MON_CUST_.
See here for more details on Custom Monitoring.Device Type [Required] Select a device from the drop-down list. Event Type Group [Required] Select the type of group for the event. Severity [Required] Severity (0 - lowest) to 10 (highest). Description Description of the event type. - Click Save.
The new event appears in the table. - Select the event(s) from the list and click Apply.
You can also use the Clone option to duplicate and modify an existing event type.
Modifying an Event Type
Complete these steps to modify an event type:
- Select one or more event attribute(s) to edit from the list.
- Click the required option from the following table.
- Edit - To modify the settings of a selected event(s).
- Delete - To delete an event type.
- Click Save.