Created on
10-31-2025
04:53 AM
Edited on
10-31-2025
06:39 AM
By
Jean-Philippe_P
| Description | This article describes how to configure an alert mail for SD-WAN SLA events with the help of the Message log attribute. |
| Scope | FortiGate. |
| Solution |
If any of the SD-WAN Link SLA statuses get changed, it will show the respective Message log in the System Events -> SD-WAN Events.
Configure automation action via GUI under Security Fabric -> Automation -> Action, select 'Create New' -> Email, and make sure the alertmail configuration is working correctly.
Configure the automation trigger via GUI under Security Fabric -> Automation -> Trigger, select 'Create New' -> FortiOS Event Log, select 'Event', filter the events to SD-WAN, and then enable the required event logs from the available SD-WAN event logs. The minimum required would be SD-WAN status information and SD-WAN status.
In the Field filter(s) -> Field name -> 'msg'. In the Value section, add the Message that is visible in the SD-WAN Event logs.
For example:
Member status changed. Member out-of-sla.
Or:
Member status changed. Member in SLA.
Now, if any of the SD-WAN SLA status goes down, the log will be generated with the configured message (Member status changed. Member out-of-sla.), and the email will be triggered.
config system automation-trigger
Note: Log ID 22933 is for 'SD-WAN SLA notification' when the interface status changes from down to up. Log ID 22931 is used for up to down status change
diagnose debug disable |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.