FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
tnaik
Staff
Staff
Article Id 190917

Description

 

This article describes how to create an Event handler in FortiAnalyzer for Policy deletion in FortiGate and send an email to the administrator.
When FortiGate sends logs to a FortiManager with FortiAnalyzer features enabled, it is possible to use the same event handler.

Solution

 

  1. Create a mail server.

    Login to FortiAnalyzer, navigate to System setting -> Mail server, and select 'Create new'.

    After, enter the mail server details.

 


  1. Test Email server working status.

    Select 'Mail Server' and select the mail server created in Step 1. After, select 'Test'.
    A notification message will pop up immediately on the same page.
 
 
  1. Login to FortiAnalyzer, navigate to Incident and Event -> Event Handler list, and select 'Create new'.
    Enter the details as per the following screenshot, and on the same page, enter the email notification details:
     
    To: Destination Email address.
    From: Source Email address which is present in the mail server.
    Mail Server: Created in 1.
    Generic text: cfgpath=firewall.policy.
    Log Description: Object configured.
    Action: Delete.
 
 
Test:
 
Upon trying to delete any test policy in FortiGate, an email notification will be received at the email address mentioned.
 
Test output:
 

 

Related articles: