FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
psalian
Staff
Staff
Article Id 190511
Description
The article describes the steps on how to configure email alerts for configuration and policy status changes on FortiManager.

Solution
1. Enable FortiAnalyzer feature
Event handler is a FortiAnalyzer feature, thus needs to be enabled under System Settings > Dashboard > System Information.



2. Under System Settings > Event logs, you will see events when the configuration status or policy status is changed.
Both events will be logged under separate log types.

For policy changes:
 


For configuration changes:
 


3. Configure email server.
Alerts will be sent using this email server
It is configured under System Settings > Mail Server
 


4. Create an event handler for both conditions
Under Event Management > Event Handler list > Create new

Event handler for configuration status changes:
 

 
Event handler for policy status changes:
 


When there is an event log generated for the status changes and when it matches the events configured in the event handler, an email is sent with details about the event to the email addresses configured in the notification section.


Contributors