I created a new event handler to notify me of all the sslvpn logins, I've rather done that from fortigate but it seems it's only capable of notifying failed logins. The issue is that I can't find a setting so all the events are sent by mail, only the ones triggering the interval defined (see the attached screenshot from the manual)
Is there any way to accomplish that? I am currently using 1match in a 1 minute period to get the alerts.
EDIT; Forgot to add that I'm using FAZ 5.2.1
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
There is no way in GUI and CLI to trigger a separate event for each log in FAZ 5.2.1.
You want every log that has the sslvpn login event to be treated as a separated alert? For example, if John Doe logged in 3 times within last 60 seconds, you want 3 alerts to be sent to you not 1 alert?
If so, I don't think there is a setting for you to do that from GUI.
L.Clarke wrote:Do you know if it would be possible to be achieved by using the cli?You want every log that has the sslvpn login event to be treated as a separated alert? For example, if John Doe logged in 3 times within last 60 seconds, you want 3 alerts to be sent to you not 1 alert?
If so, I don't think there is a setting for you to do that from GUI.
There is no way in GUI and CLI to trigger a separate event for each log in FAZ 5.2.1.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.