FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
tnaik
Staff
Staff
Article Id 190399

Description

 

This article describes how to create an event handler in FortiAnalyzer for a Policy change in FortiGate and send an email to the administrator.

Solution

 

  1. Create a mail server.

    Log in to FortiAnalyzer, go to System setting -> Mail Server and select 'Create new'.

    Now enter the mail server details.

 
  1. Test the email server working status.

    Select 'Mail Server' and select the mail server created in step 1. After, select 'Test'.

    A notification message pops up immediately on the same page.
     
     
  2. Log in to FortiAnalyzer, go to Incident and Event -> Event Handler list, and select 'Create New'.

    Enter the details below:
 
  
 
Now, on the same page, enter the notification details:
 
To: destination email address.
 
From: source email address which is present in the mail server.
 
Mail Server: created in Step 1.
  
 
Test.

Try to change any policy in FortiGate that receives email notifications on the email address mentioned.
 
Related articles: