Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MasaruO
New Contributor

How to receive emails only for high-priority alerts with compromised hosts detected by FortiAnalyser

Hello. Please help me. Currently, I have set up FortiAnalyzer to send an email to the administrator when a compromised host is detected. However, since I receive notifications for everything detected, I end up missing critical ones. I want to receive emails only for high-priority alerts. Is there a way to do this? If it cannot be done with the standard settings, I would like to use an API or other method to achieve this.

1 REPLY 1
jasonhong
Staff
Staff

Hi,

 

You can actually use the predefined event handler (Default-Compromised Host-Detection-IOC-By-Threat) in FAZ which will only be triggered based on the rule which includes Event Severity = Critical.

 

https://docs.fortinet.com/document/fortianalyzer/7.2.5/administration-guide/778986

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors