Skip to main content
smkml
Staff
Staff
August 26, 2025

Technical Tip: FortiAnalyzer uses webhook to send alert to Webhook site

  • August 26, 2025
  • 0 replies
  • 1483 views

Description

 

This article describes how to send an alert message from FortiAnalyzer to a Webhook site.

 

using a generic connector.png

 

Scope

 

FortiAnalyzer.

 

Solution

 

When accessing the webhook site, it will generate a unique URL, as is generally the case.

 

webhook unique URL.png

 

  1. Use the unique URL to put in under the Generic Connector URL value:

  • In v7.4.x, go to Fabric View -> Fabric Connectors  -> Create New -> Generic Connector.

  • In v7.6.x, go to Incidents & Events -> Automation -> Active Connectors -> Create New -> Generic Connector.

 

unique URL under generic connector.png

 

Other than the URL value, it is only mandatory to put in the following value:

 

Protocol

HTTPS

Port

443

Method

POST

 

Authentication is not necessary for this setup and can be ignored, as HTTP bodies are optional for a meaningful message display in the alert.

The text output for the ${} sign can be replaced using other Configuring ITSM connectors in (Supported macros for the MS Teams Connector).

 

  1. Add the created webhook to the Notification Profile.

  • In v7.4.x, go to Incidents & Events -> Handlers -> Notification Profiles -> Create New.

  • In v7.6.x, go to Incidents & Events -> Event Handlers -> Notification Profiles -> Create New.

 

notification profile.png

 

  1. Create an event and add the notifications profile to it.

  • In v7.4.x, go to Incidents & Events -> Handlers -> Basic Handlers -> Create New.

  • In v7.6.x, go to Incidents & Events -> Event Handlers -> Event Handlers -> Create New.

 

handlers using notification profiles.png

 

  1. Trigger the event and check if it is present in the Event Monitor and the webhook site.

 

event monitor triggered.png

 

webhook site output sample.png

 

Notice: Alerts sent in JSON format using ITSM Connectors.

 

Debug to see the output from the FortiAnalyzer to the connector after configuration:

 

diagnose debug enable
diagnose debug timestamp enable
diagnose debug application fazsvcd 255
diagnose debug application faznotify 8

 

To disable the debugging:

 

diagnose debug disable

 

If the connection to the Webhook site is flapping, run these debug commands for 30 to 45 minutes and share the results with Support:

 

diagnose debug application faznotify 8
diagnose debug timestamp enable
diagnose debug enable

 

Afterwards, obtain the RC code:


diagnose debug application faznotify 0

 

To disable the debug process:

 

diagnose debug disable

 

After disabling the debug processes, capture the output of the following:


diagnose test application faznotify 2
diagnose test application faznotify 3 * *
diagnose test application faznotify 1 (show the daemon info)
diagnose test application faznotify 2 (show faznotify statistics)
diagnose test application faznotify 20 (show the count of active channels at that moment)
diagnose test application faznotify 3 <adom> <webhook-name> (show statistics of the specific connector)

 

Attach the debug output to a new ticket through the support portal: Ticketing.

 

Related documents:

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!