FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
Article Id 194727


This article describes how to configure email alerts for failed login using FortiAnalyzer event handler.


1) Setup a mail server at system settings -> Advanced -> Mail Server.

2) Create a new event handler at Incidents & Events -> Handlers -> Event Handler List.
In the newer versions of FortiAnalyzer (6.4.x), Incidents and Events have been replaced by FortiSoc.

3) Set the 'Log Device Type' as 'FortiGate' and 'Log Type' as 'Event Log'.
On 'Log Field', select 'Log ID'.
Enter value '0100044546” and '0100044547'.
4) Select 'Send Alert Email'.
Enter the email address and select the 'Email Server' that was created earlier.
5) Log ID information can be check from the received logs on 'Log View'.
'Log ID' can be use to filter different log for example, admin login / logoff, FortiAnalyzer disconnection.