FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
larsbollas
Staff
Staff
Article Id 353276

 

Description This article describes how to enable Email alerts whenever an anomaly is detected.
Scope FortiGate v7.2. 
Solution
  1. Make sure a DOS policy is in place and logging is enabled.

    dos policy.PNG
    Refer to this article: Technical Tip: How to configure IPv4 DOS policy.

  2. Go to Security Fabric -> Automation -> Trigger -> Select Create New -> Select Anomaly Logs.
                                                                                         

trigger.png

 

  1. Set the name for the Anomaly Logs Automation Trigger, then select OK:


    anomaly logs.PNG

     

  2. Go to Security Fabric -> Automation -> Action -> Select Create New:

    • Set the Name.
    • Interval time can be configured.
    • Set the Email from, Email recipient, and Email subject.
    • Leave the body "%%log%%" as default.


action.png

 

  1. Go to Security Fabric -> Automation -> Stitch -> Select Create New.

    • Set the Name.
    • Set the Status to 'Enable'.
    • Set Action execution to 'Sequential'.
    • Under Stitch, select the newly created trigger for Anomaly Logs and action to Email Notification.
    • Select OK.

     

auto.PNG

 

automation stitch.png

 

Result:


result.png

 

An email notification will be sent to the recipient's Email address when the FortiGate DOS policy threshold is triggered or an anomaly is detected.