FortiSIEM Event Categories and Handling
This topic provides a brief description of various types of event categories in FortiSIEM.
| System Event Category |
Description | Counted in EPS License |
phstatus -a outout |
Stored in DB? |
|---|---|---|---|---|
| 0 | External events and not flow events (e.g. syslog, SNMP Trap, Event pulling) | Yes | EPS | Yes |
| 1 | Incidents (events that begin with PH_RULE) | No | EPS INTERNAL | No |
| 2 | FortiSIEM Audit Events (events that begin with PH_AUDIT) | No | EPS INTERNAL | Yes |
| 3 | FortiSIEM Internal system logs, free format | No | EPS INTERNAL | Yes |
| 4 | External flow events (Netflow, Sflow) | Yes | EPS | Yes |
| 5 | FortiSIEM Internal health events for summary dashboards | No | EPS INTERNAL | Yes |
| 6 | FortiSIEM Performance Monitoring events (events that begin with PH_DEV_MON) | Yes | EPS PERF | Yes |
| 7 | AO Beaconing events | No | EPS INTERNAL | Yes |
| 8 | FortiSIEM Real Time Performance Probe Events | No | EPS INTERNAL | No |
| 99 | FortiSIEM Internal Rule Engine | No | EPS INTERNAL | No |
| 1,100 | Incidents (events that begin with PH_RULE). When using "System Event Category IN 1,100" the eventDB is queried for incident events. Every time an incident is triggered, including subsequent triggers of the same incident an event is stored in the eventDB. | No | EPS INTERNAL | Yes |