I made a configuration to receive an e-mail message when my link goes down, but I would like to know which link went down, I'm using event 20099, I tried to configure event 20090 but I don't receive an e-mail.
Is there any way to receive the name of the dropped link or interface?
Solved! Go to Solution.
Hello @Marcos_FDS1012 ,
There won't be a different event ID based on different interface, You should be able to see in the email in the raw log which interface was down
date=2024-08-05 time=11:11:08 eventtime=1722870669172337133 tz="-0400" logid="0100020099" type="event" subtype="system" level="warning" vd="root" logdesc="Interface status changed" action="interface-stat-change" status="DOWN" msg="Link monitor: Interface internal7 was turned down"
Hello @Marcos_FDS1012 ,
There won't be a different event ID based on different interface, You should be able to see in the email in the raw log which interface was down
date=2024-08-05 time=11:11:08 eventtime=1722870669172337133 tz="-0400" logid="0100020099" type="event" subtype="system" level="warning" vd="root" logdesc="Interface status changed" action="interface-stat-change" status="DOWN" msg="Link monitor: Interface internal7 was turned down"
Hello @Marcos_FDS1012,
Please review https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-an-automation-stitch-to-g... and https://community.fortinet.com/t5/FortiGate/Technical-Tip-Automation-stitch-test-related-to-event-lo... for further clarification on how to configure an automation stitch using a specific event log ID from the Logs on FortiGate.
Thanks,
Ronak Patel
User | Count |
---|---|
2677 | |
1412 | |
810 | |
703 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.