Created on
05-22-2023
04:58 AM
Edited on
06-24-2025
12:35 AM
By
Jean-Philippe_P
| Description | This article describes how to create an automation stitch admin user login and logout. |
| Scope | FortiGate v6.4 and above. |
| Solution |
FortiGate creates a log when an Admin user logs in and logs out the FortiGate.
Login event:
date=2023-05-22 time=13:17:26 eventtime=1684754246523091187 tz="+0200" logid="0100032001" type="event" subtype="system" level="information" vd="root" logdesc="Admin login successful" sn="1684754246" user="admin" ui="https(10.32.22.111)" method="https" srcip=10.32.22.111 dstip=10.40.19.15 action="login" status="success" reason="none" profile="super_admin" msg="Administrator admin logged in successfully from https(10.32.22.111)"
Logout event:
date=2023-05-22 time=13:18:34 eventtime=1684754314759921964 tz="+0200" logid="0100032003" type="event" subtype="system" level="information" vd="root" logdesc="Admin logout successful" sn="1684754246" user="admin" ui="https(10.32.22.111)" method="https" srcip=10.32.22.111
For monitoring and documentation, it is possible to create an automation in the FortiGate to send the alert mail when an admin user logs in and logs out of the FortiGate.
To create an automation stitch, check the following steps:
Configure the email server in FortiGate.
From GUI:
Go to System -> Settings -> Email Service.
It is possible to use the default setting with notification.fortinet.net as an email server or use custom settings.
From CLI:
config system email-server
Configure automation:
Navigate to Security Fabric -> Automation -> Under Stitch tab, Create New:
For v7.4.x versions and above:
Navigate to Security Fabric -> Automation -> Trigger tab -> Create New:
Then go to Security Fabric -> Automation -> Action tab -> Create New:
Configure the stitch under Security Fabric -> Automation -> Stitch tab -> Create New:
From CLI: Automation Stitch.
config system automation-stitch
Automation trigger.
config system automation-trigger
Automation action.
config system automation-action
Result : When the user logs in and logs out of the firewall, an alert email with the log will be sent.
noreply@notification.fortinet.net FGT[FGVM010000017397] Automation Stitch:Admin_login is triggered.
FGT[FGVM010000017397] Automation Stitch:Admin_logout is triggered.
Note: Starting with FortiOS v7.4.4, the default email server has been switched from notification.fortinet.net to fortinet-notifications.com. This default server is only available to registered devices with an active FortiCare support contract. The reply-to field in the source email is automatically updated to DoNotReply@fortinet-notifications.com for all servers, including custom ones.
Related documents: Technical Tip: How to enable the email alerts when the Interface is down and up |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.