FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
msanjaypadma
Staff
Staff
Article Id 353555
Description

 

This article describes generating email alerts for a single CPU core spike.

 

Scope

 

FortiGate.

 

Solution

 

Refer below steps to configure the automation stitch for generating mail alerts for a single CPU core spike.

 

  1. Navigate Security Fabric and select Automation.
     
    Capture11.PNG

 

  1. Select Create New to create a new automation stitch.

    capture12.PNG

     

     

  2. Configure the Name and enable the status.

     

  3. Select Add Trigger to configure the trigger condition and then select Create New and then FortiOS Event Logs.

     

    Capture13.PNG

     

  4. Configure the Name, select FortiOS Event ID: 40707, and select OK.
                                                                            

    capture14.png                                                         

     

  5. Once Automation Trigger is configured, apply the object to Trigger.

  6. Select Add Action and New or select an existing email notification action.

  7. After selecting New, select the Email option from the notification. 

  8. Configure the fields Name, From, To, and select OK.
                                                            

    Capture16.PNG

  9. Select OK.

                                                         

capture17.PNG

 

Make sure the below command is enabled to log the event. Any single CPU core usage above the CPU usage threshold will report an event log.

 

config system global
    set log-single-cpu-high enable
end

 

To make sure that the email daemon is working as expected, a test log email alert can be generated using the command: diagnose log alertmail test.

 

Related article:

Technical Tip: How to configure alert email settings