Blogs

FortiAnalyzer Admin Action Event Handler

Kevin Guenay

Kevin Guenay

20 Jul 2026

FTNT_TechXperts_1024x600px_260520.jpg

Administrator activities are among the most important Indicators of Compromise (IoCs) on a system. These activities include the creation of new administrator accounts as well as the modification or deletion of existing administrator accounts. 

As a log aggregation and analysis platform, FortiAnalyzer provides visibility into such activities and can initiate various automated response actions. For example, it can create incidents, trigger playbooks, send email notifications, or initiate additional security measures. This enables security teams to detect potential threats early and respond to them efficiently. 

To start this chain, you first need an event handler for this and this is what we are going to look at in this article.

The setup:

  • FortiGate 70G on 7.6.7
  • FortiAnalyzer on 7.6.7
  • FortiManager on 7.6.7
  • FortiClient EMS on 7.4.7

All devices send logs to FortiAnalyzer.

To configure logging to FortiAnalyzer, it’s best to consult the official Fortinet documentation.

FortiGate:

FortiManager:

FortiClient EMS (not for FortiClient):

The Event Handler

For easy deployment, the Event Handler can be downloaded from the following link: Exclusive Networks download link for configurations. 

After downloading the file, the Event Handler can be imported into FortiAnalyzer using the Import button in the Event Handlers menu. 

Exclusive Networks is not liable for any problems caused by using any of the provided configurations. 

The event handler currently covers FortiGate, FortiManager, FortiAnalyzer, and FortiClient EMS, and each system has its own rule in the format “SYSTEM-ADMIN-ACTION”, e.g. “FGT-ADMIN-ACTION”. 

After the import, events should be created if the following actions happen on a device and the logs arrive on FortiAnalyzer. 

FortiGate:

  • Local, remote, SSO, and API administrators are being created, edited or deleted
  • New keys for API administrators are being generated
    • You need to enable REST API event logging for this

FortiManager/FortiAnalyzer:

  • Local, remote, SSO, and API administrators are being created, edited or deleted

FortiClient EMS:

  • Local, remote, SSO, and API administrators are being created, edited or deleted
  • The logging for administrator events on EMS is a bit weird because lots of things appear to use Log ID 6, including logins (failed and successful) and the relevant events for this article. If you look at such an administrator log, you can also see that the Message field is not available, which makes filtering difficult. I sadly do not know all the things that use this log ID, but I have excluded logins using regular expressions.

If relevant logs appear, events will be created. The event handler can, of course, be changed, and notification profiles can be configured to send mails, or you can use the event handler as a trigger for playbooks.

The event handler does not create incidents.

In the Additional Info field on the event is some more information depending on the system.

  • FortiGate: The complete message, meaning what got changed and which IP caused the change
  • FortiManager/FortiAnalyzer: The change path and which IP caused the change

faz_fgt_events.png

faz_faz_events.png

Session Close

A quick topic, we hope that this event handler can help you in the future.

If you have suggestions for future posts, would like to see configurations, also in video format, or want to give feedback, please send them to techxperts_central@exclusive-networks.com

Latest blogs

View all Blogs

Start growing your business

Whether you need a quote, advice, want to become a partner, or want to take advantage of our global services, we are here to help.

Get in touch