Working with Event Types

After parsing an event or log, FortiSIEM assigns a unique event type to that event/log. When you create a new custom parser for device logs, you have to add a new event type to FortiSIEM so the log events can be identified.

This section provides the procedure to create event types.

Adding an event type

Follow the procedure below to add an event:

  1. Go to ADMIN > Device Support> Event tab.
  2. Click New
  3. In the Event Type Definition dialog box, enter the information below.

    SettingsGuidelines
    Name[Required] Event type name - must begin with "PH_DEV_MON_CUST_"
    Display Name[Required] Display name of the event type
    Event Type Group[Required] Select the type of group for the event
    Severity[Required] Severity (0 - lowest) to 10 (highest)
    DescriptionDescription of the event type
  4. Click Save.
    The new event appears in the table.
  5. Select the event(s) from the list and click Apply.

Modifying an event type

Follow the procedure below to modify an event type:

  1. Select one or more event attribute(s) to edit from the list.
  2. Click the required option from the following table.
    • Edit - To modify the settings of a selected event(s).
    • Delete - To delete an event.
    • Clone - To duplicate an event.
  3. Click Save.