Cloning event handlers
Cloning an event handler allows you to build a custom event handler by using an existing one as a template.
Most attributes in a predefined event handler cannot be modified, such as the name, description, and rule settings. You can, however, clone a predefined event handler to customize its settings and give it a meaningful name to show its function.
To clone an event handler:
- Go to FortiSoC/Incidents & Events > Handlers > Event Handler List.
If cloning a correlation handler, go to FortiSoC/Incidents & Events > Handlers > Correlation Handler List.
- Select an event handler and in the toolbar and click Clone.
You can also right-click the event handler and select Clone.
- Configure the cloned event handler. For a description of the fields, see Creating a custom event handler or Creating a custom correlation handler.
Use a descriptive name so it is not confused with the event handler it was cloned from.
- Click OK save the cloned event handler.