Triggers
The following table outlines the available triggers.
Category |
Trigger |
Description |
---|---|---|
Security Fabric |
||
|
Compromised Host |
An indicator of compromise (IoC) is detected on a host endpoint. The threat level must be selected and can be Medium or High. If Medium is selected, both medium and high level threats are included. Additional actions are available only for Compromised Host triggers:
|
|
Fabric Connector Event |
An event has occurred on a specific Fabric connector. See Fabric connector event trigger for details. |
|
FortiAnalyzer Event Handler |
The specified FortiAnalyzer event handler has occurred. See FortiAnalyzer event handler trigger for details. |
|
FortiGate Cloud-Based IOC |
IOC detection from the FortiGate Cloud IOC service. This option requires an IOC license, a web filter license, and FortiCloud logging must be enabled. |
|
FortiGate Cloud Event Handler |
The specified FortiGate Cloud event handler has occurred. This option requires a FortiGate Cloud log retention license. |
|
Security Rating Summary |
A summary is available for a recently run Security Rating report. Options include:
|
System |
||
|
AV & IPS DB Update |
The antivirus and IPS database is updating. |
|
Configuration Change |
A FortiGate configuration change has occurred. |
|
Conserve Mode |
A FortiGate entered conserve mode due to low memory. See Execute a CLI script based on CPU and memory thresholds for an example. |
|
HA Failover |
An HA failover is occurring. |
|
High CPU |
A FortiGate has high CPU usage. See Execute a CLI script based on CPU and memory thresholds for an example. |
|
License Expiry |
A FortiGuard license is expiring. The license type must be selected. Options include:
|
|
Local Certificate Expiry |
A local certificate is about to expire. See Certificate expiration trigger for an example. |
|
Reboot |
A FortiGate is rebooting. |
Event Log Category |
||
|
Anomaly Logs |
An anomalous event has occurred. See Event log category triggers for an example. |
|
IPS Logs |
An IPS event has occurred. |
|
SSH Logs |
An SSH event has occurred. |
|
Traffic Violation |
A traffic policy has been violated. |
|
Virus Logs |
A virus event has occurred. |
|
Web Filter Violation |
A web filter policy has been violated. |
Miscellaneous |
||
|
FortiOS Event Log |
The specified FortiOS log has occurred. Multiple event log IDs can be selected, and log field filters can be applied. See FortiOS event log trigger for an example. |
|
Incoming Webhook |
An incoming webhook is triggered. |
|
Schedule |
A scheduled monthly, weekly, daily, hourly, or one-time trigger. Set to occur on a specific minute of an specific hour on a specific day. When using the one-time trigger, set to occur on specific date and time in the future. See Schedule trigger for an example. |