Creating a Custom Performance Monitor
You can create Custom Performance Monitors by defining the performance object that you want to monitor, including the relationship between the performance object and FortiSIEM events and event attributes, and then associating the performance object to a device type.
Creating Custom Performance Monitors for Enterprise and Multi-Tenant Deployments
In Service Provider FortiSIEM deployments, custom performance performance have to be created by the Super/Global account, and apply to all organizations. In enterprise deployments, custom performance monitors can be created by any user who has access to the Admin tab.
Prerequisites
- You should review the configuration settings for the monitoring protocols that you will use in your monitor, and be ready to provide the appropriate OIDs, classes, or database table attributes for the access protocol.
- You should have created any new device/application types, event attributes, or event types that you want to use in your Performance Monitor.
- You should have the IP address and access credentials for a device that you can use to test the monitor.
Creating the Performance Object and Applying it to a Device
- Go to ADMIN > Device Support > Monitoring.
- Click New.
- Enter a Name for the Performance Monitor.
- For Type, select either System or Application.
- For Method, select the monitoring protocol for the performance monitor.
See the topics under Monitoring Protocol Configuration Settings for more information about the configuration settings for each type of monitoring protocol. - Click New next to List of Attributes, and create the mapping between the performance object and FortiSIEM event attributes.
Note that the Method you select will determine the name of this mapping and the configuration options that are available. See Mapping Monitoring Protocol Objects to Event Attributes for more information. - Select the Event Type that will be monitored.
- Enter the Polling Frequency for the monitor.
- Enter a Description.
- Click Save.
- Under Enter Device Type to Performance Object Association section, click New.
- Enter a Name for the mapping.
- Select the Device Type from the drop-down for which you want to apply the monitor.
Whenever a device belonging to the selected device type is discovered, FortiSIEM will attempt to apply the performance monitor to it. - Click Perf Objects drop-down to select or search the Performance Objects.
- Click Save.
Testing the Performance Monitor
- Go to ADMIN > Device Support > Monitoring.
- Select the performance monitor.
- Click Test.
-
For IP, enter the IP address of the device that you want to use to test the monitor.
Testing for Multi-Tenant Deployments: If you have a Service Provider FortiSIEM, select the Supervisor or Collector where the device is monitored. - Click Test.If the test succeeds, click Close, and then click Apply to register the new monitor with the back-end module.
After you have successfully tested and applied the performance monitor, you should initiate discovery of the device that it will monitor, and then make sure that the new monitor is enabled as described in Managing Monitoring of System and Application Metrics for Devices.