Skip to main content
fmoh
New Member
June 22, 2016
Question

FortiAnalyzer Email Alerts - Custom Queries

  • June 22, 2016
  • 7 replies
  • 10816 views

Hello,

For reference I am using FortiAnalyzer-VM64

 

Essentially, I have been able to create a custom query for the web filter log to retrieve counts of source IP addresses, and display the top 15 highest occurring results. From this dataset I was able to create automatic email alerts using the reporting system, however instead of a PDF attachment I would like the results from the query to be displayed as plain text in the email message.

 

Is there any way for me to get the results of my query to be raw text in an automatic email alert? When our mail server receives the email it automatically parses the message for the relevant information, however this is not possible if the message is a PDF attachment in a report format.

 

Thanks for your help

7 replies

hzhao_FTNT
Staff
Staff
June 22, 2016

Hi there,

 

Unfortunately we do not offer plain text in email output

On FAZ 5.4, you can choose PDF/HTML/XML/CSV

On FAZ 5.2, you can choose PDF/HTML, the html report is in a zipped folder.

 

 Regards,

hz

fmoh
fmohAuthor
New Member
June 22, 2016

Thanks for the answer.

 

However, whenever I select HTML in the output profile, the email never gets sent. It only seems to work for PDF.

Is there a way to get the HTML file sent through email? As you suggested I would expect it as a zip attachment.

 

Thanks

hzhao_FTNT
Staff
Staff
June 22, 2016

The HTML report could be blocked by mail server because it contains some JS files, please check with your mail server admin and ask him to give you an exception.

 

regards,hz

rhap4boy
Visitor III
March 23, 2022

Hi fmoh,

 

How do you create a custom query for the web filter log to retrieve counts of source IP addresses and display the top 15 highest occurring results?  I was wondering if you can share that query info?  Thank you!

Debbie_FTNT
Staff & Editor
Staff & Editor
March 24, 2022

Hey rhap,

I'm not fmoh, but I do have some experience with FortiAnalyzer datasets :).

The query would look something like this:

 

select count(srcip) as source

from $log

where $filter

group by srcip limit 15

 

When creating the dataset, set Log Type to 'Web Filter':

Debbie_FTNT_0-1648109713582.png

Then map the dataset to a chart, and add that chart to a report :)

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!