Skip to main content
its-chain
New Member
June 12, 2022
Question

Alert for specific Policy ID

  • June 12, 2022
  • 6 replies
  • 3865 views

Hi,

I trying to set alert for only specific policy violation.

I tried to enable 

set violation-traffic-logs [enable|disable]

but I receiving a lot of other alerts.

my request can be done?

thanks for the help

Daniel

6 replies

seshuganesh
Staff
Staff
June 13, 2022

Hi Team,

 

If you want to view logs for specific firewall policy, click on that policy and enable logging for that policy in the end of that policy.

If you want to view implicit deny firewall policy logs, you can use this article:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Implicit-deny-logs/ta-p/194602

Please check and keep us posted

its-chain
its-chainAuthor
New Member
June 13, 2022

Hi,

thanks for your respone.

I know how to enable logs.

My goal is to set a policy for blocking malicious IP's and receive a notification only for this policy.

Contributor III
June 13, 2022

Hi there,

Based on my understanding, you have multiple Policy and would like to enable logging for specific policy only. 

 

Example:
Policy 1-3 : Enable logging
Policy 4-5 : No logging

 

On policy 4-5, edit each of this policy and turn off "Log Allowed Traffic".

On policy 1-3, enable the "Log Allowed Traffic".

Hope that helps.

 

 

its-chain
its-chainAuthor
New Member
June 13, 2022

Hi,

thanks for your response.

I know how to enable logs.

My goal is to set a policy for blocking malicious IPs and receive a notification only for this policy.

Contributor III
June 15, 2022

Hi its-chain,
I think i understand your requirements now.
If the IP is blocked by IPS, you can send email alert. If you are blocking using policy IPv4, this cannot be done.


Here is the reference: https://docs.fortinet.com/document/fortigate/6.2.7/cookbook/526019/email-alerts

Hope that helps.

pminarik
Staff
Staff
June 13, 2022

As far as I can see, it isn't possible to do what you're looking for with FortiGate alone.

Alertmail configuration is too vague (on/off for "violation traffic"), and automation stitches do not allow triggering events based on forward traffic logs (checked 7.0.5 & 6.4.9, not sure about 7.2).

 

However, if you have a FortiAnalyzer, you should be able to put something together with its Event Handler. If you're looking for some documentation for that, you can start here .

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!