FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
Description The article describes the steps on how to configure
email alerts for configuration and policy status changes on
FortiManager.
Solution 1. Enable
FortiAnalyzer feature
Event handler is a FortiAnalyzer feature, thus needs to be enabled
under System Settings > Dashboard > System
Information.
2. Under System Settings > Event logs, you will see
events when the configuration status or policy status is
changed.
Both events will be logged under separate log types.
For policy changes:
For configuration changes:
3. Configure email server.
Alerts will be sent using this email server
It is configured under System Settings > Mail
Server
4. Create an event handler for both conditions
Under Event Management > Event Handler list > Create
new
Event handler for configuration status changes:
Event handler for policy status changes:
When there is an event log generated for the status changes and
when it matches the events configured in the event handler, an
email is sent with details about the event to the email addresses
configured in the notification section.