Does anyone know if it is possible to setup email alerts for DLP logs on Fortigate 5.2? From what I can see there isn't a pre-baked option. Is it possible to setup customized alerts from the CLI?
Hi
for email alerting following can be configured (no possibility for DLP):
config alertemail setting set username <user-name_str> set mailto1 <email-address_str> set mailto2 <email-address_str> set mailto3 <email-address_str> set filter-mode {category | threshold} set email-interval <minutes_int> set emergency-interval <minutes_int> set alert-interval <minutes_int> set critical-interval <minutes_int> set error-interval <minutes_int> set warning-interval <minutes_int> set notification-interval <minutes_int> set information-interval <minutes_int> set debug-interval <minutes_int> set severity {alert | critical | debug | emergency | error | information | notification | warning} set IPS-logs {disable | enable} set firewall-authentication-failure-logs {disable | enable} set HA-logs {enable | disable} set IPsec-error-logs {disable | enable} set FDS-update-logs {disable | enable} set PPP-errors-logs {disable | enable} set sslvpn-authentication-errors-logs {disable | enable} set antivirus-logs {disable | enable} set webfilter-logs {disable | enable} set configuration-changes-logs {disable | enable} set violation-traffic-logs {disable | enable} set admin-login-logs {disable | enable} set local-disk-usage-warning {disable | enable} set FDS-license-expiring-warning {disable | enable} set FDS-license-expiring-days <days_int> set local-disk-usage <percentage> set fortiguard-log-quota-warning {disable | enable} end
the only thing you can do from my perspective is: if you deliver your logs to a FortiAnalyzer you can filter there the logs based on a event and if this event happens (information for DLP in the logs) a mail is send out to informe regarding this event.
On the FortiGate itself I do not see any possibility.
have fun...
Andrea
I liked Andrea's suggestion of using FortiAnalyzer but it's kind of overkill for my use case. In the end, I just setup Syslog and I have an alert for dlp messages. It'd be great if they introduce email logs for dlp directly in the product but this will work for now.
Year 2017, July 5th, FortiOS v5.6 - still no alerts for DLP !!!
maybe this is one of the minor feature/s that fortinet development could address :)
Fortigate Newbie
They wont address it because you can do it in Fortianalyser... money money moneh !!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1744 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.