FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
ckarwei
Staff
Staff
Article Id 194727

Description


This article describes how to configure email alerts for failed login using FortiAnalyzer event handler.

Solution

 

  1. Setup a mail server at system settings -> Advanced -> Mail Server.

 

 
  1. Create a new event handler at Incidents & Events -> Handlers -> Event Handler List.

    Note:
    In the newer versions of FortiAnalyzer (6.4.x), Incidents and Events have been replaced by FortiSOC.
     
  2. Set the 'Log Device Type' to 'FortiGate' and the 'Log Type' to 'Event Log'.
    Under 'Log Field', select 'Log ID'.
    Enter the values '0100044546' and '0100044547'.
 
  
  1. Select 'Send Alert Email'.
    Enter the email address and select the 'Email Server' that was created earlier.
 
  
  1. Log ID information can be checked from the received logs on 'Log View'.
    'Log ID' can be used to filter different logs, for example, admin login/logoff, and FortiAnalyzer disconnection.