FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
Nur
Staff
Staff
Article Id 293294
Description This article describes how to use the Event Handler for FortiProxy to change the 'log type' value in FortiAnalyzer.
Scope FortiProxy and FortiAnalyzer.
Solution

By default when it is necessary to create an Event Handler for FortiProxy to trigger the IPS event log, there is no option available from GUI.

 

Screenshot 2024-01-09 212814.png

 

Hence, it is necessary to edit it from the JSON file.

 

  1. Go to the Event handler created -> Select export (in the text file).

Screenshot 2024-01-09 213302.png

 

  1. Open the JSON file and search under Rule -> 'logtype' -> Change to 'IPS'.

    Screenshot 2024-01-09 213517.png

     

     

  2. After changing the 'log type' value, save it and import it again to FortiAnalyzer.

    When importing the file, ensure to choose 'rename' and select ok.

     

    Screenshot 2024-01-09 213933.png

     

  3. Go to the files renamed, change the 'Group by' value to IPS and logs match as IPS.

     

    Screenshot 2024-01-09 220103.png

     

     

  4. Test send dummy log from FortiProxy to FortiAnalyzer (diag log test).

    Screenshot 2024-01-09 220304.png

     

  5. After sending the dummy log to FortiAnalyzer, check the event handler trigger at the event monitor, and select 'All events'.

    Screenshot 2024-01-09 220525.png

Contributors