Hello!
I need to set up FortiEDR notifications for when a collector/device gets put in isolation automatically via the playbook. All of the system/security event notifications are setup and work properly, but how do I get the isolation notifications sent to the distribution lists?
Thank you!
S0ck-Pupp3t
Solved! Go to Solution.
Created on ‎02-12-2025 08:31 AM Edited on ‎02-13-2025 12:24 PM
Hi @Langflow,
Thanks for the question! To clarify, by design, if you've configured Distribution Lists for email notifications, you will only receive notifications for Security Events and System Events. There is no separate email specifically for device isolation.
For detailed tracking of isolation events, you can refer to the Audit Trail in the FortiEDR WebUI:
Go to Tools -> Audit Trail to view or download related events. If you have Syslog configured, the syslog output will include entries from the Audit Trail, including isolation events.
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Thank you!
To receive email notifications when a FortiEDR Collector is isolated, you need to ensure that the playbook is set correctly.
Here are the steps to set up email notifications for isolation events in FortiEDR:
Hi @Anthony_E,
Thank you for this information. Points # 1 & 2 are what I'm struggling with. I have notifications enabled for every event type from Likely Safe to Malicious and the checkbox to Isolate the device is also checked on Malicious. I am on Version 6.2.1 and I don't see an option to notify on isolations. In the email notifications section where distribution lists are created, I have system events and security events enabled (and those work fine).
Is there something else that needs to be enabled or am I missing something?
Thank you in advance!
Hi @S0ck-Pupp3t,
FortiEDR does not send a separate email through the distribution list specifically for device isolation. Instead, when a device executes a malicious file and is automatically isolated, you will receive a Security Event Notification email.
To verify your setup, please check your Playbook settings under the Security Settings tab:
Email notifications for FortiEDR isolation would be super helpful! If anyone has set this up successfully, I'd love to know the best way to configure it.
Created on ‎02-12-2025 08:31 AM Edited on ‎02-13-2025 12:24 PM
Hi @Langflow,
Thanks for the question! To clarify, by design, if you've configured Distribution Lists for email notifications, you will only receive notifications for Security Events and System Events. There is no separate email specifically for device isolation.
For detailed tracking of isolation events, you can refer to the Audit Trail in the FortiEDR WebUI:
Go to Tools -> Audit Trail to view or download related events. If you have Syslog configured, the syslog output will include entries from the Audit Trail, including isolation events.
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.