Hi,
I’m trying to use FortiAnalyzer (FAZ) to monitor IPsec tunnel down events in a large-scale SD-WAN.
Event Handlers are in place and SMTP email alerts are configured, but I’m seeing:
IPsec down events don’t always generate alerts.
FAZ is at HQ. When the branch-to-HQ IPsec tunnel drops, FAZ doesn’t trigger the down alert. I usually get a “down + up” alert only after the tunnel comes back up, which isn’t useful.
If this isn’t a valid use case for FAZ, what’s the recommended way to achieve timely alerts? Can FAZ generate a “device disconnected” or “device down” event when a FortiGate loses connectivity to FAZ? That would be more meaningful once the tunnels drop.
Solved! Go to Solution.
You need to check the log of FAZ and create a event from it, not the log from ADOM.
In that case, you can configure the FAZ alert if not recieve log from FG after x minutes.
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-Creating-alerts-when-FortiAnalyzer-sto...
Still, it's not generating events correctly- Our FAZ version is 7.4. Are there any other options?
What do you mean by not generating event correctly? It match your situation when FG loses connection to FAZ via VPN connection, it also avoids false alert if tunnel up/down continuously.
There is an event being generated in FAZ > System Settings > Event Log, but the event handler is not generating any alerts with the above KB configuration.
The Event Handler is configured with desc=="Device offline" in the Generic Text Filter. This may be because the options are not the same in version 7.4. In this version, there is only Log Filter by Text, located inside the Rules section, not in the main Event Handler settings.
I also using 7.4 FAZ, it work until now. You need to check at the first step that FAZ generate the log with "Did not receive any log from device XXX in past X minutes"
Still not getting the event triggered. I have the ADOM enabled in the FAZ, and where I am trying this event handler is not the root ADOM.
You need to check the log of FAZ and create a event from it, not the log from ADOM.
Hi,
I moved this post to the support forum.
Regards,
Hi Sambhu,
Can you confirm this request is closed, or do you still need some assistance?
Thank you in advance
Joanne
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2677 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.