Dear Everyone,
Currently we are configuring automation-stitch to send alert to our platform for anonymous login to FortiGate GUI.
I tried to configure the trigger with specific condition.
- if user A try to access to dashboard and failed login for more than 3 times, automation-stitch must consider this is bruteforce attack.
- if user B try to access to dashboard and failed login for under 3 times, the automation-stitch must also trigger this alert but consider it is not bruteforce attack.
Kindly provide me some ideas regarding to this.
Thank you.
Joy
To configure an automation stitch for different conditions based on failed login attempts, you can follow these steps:
Define Event Handlers: Create two separate event handlers in FortiAnalyzer for each condition.
Configure Automation Stitch:
Set Up Actions:
Test the Configuration:
Monitor and Adjust:
By setting up separate event handlers and automation stitches for each user condition, you can effectively manage and respond to different types of login attempts.
Best regards,
Erlin
| User | Count |
|---|---|
| 2787 | |
| 1423 | |
| 812 | |
| 746 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.