Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
albaker1
Contributor

Too many admin login/logout email alerts from localhost

We recently re-implemented alerting for admin logins and logouts on a FortiGate that currently isn't deployed - the firewall is mostsly for testing a few capabilities and features before rolling them out to the other firewalls. The problem is that localhost is logging into the firewall, and in the past 8 hours, it's logged in 18 times - anywhere from a few minutes to 45 minutes. This makes the admin login alerting useless.

 

FortiGates are running 7.2.5 and FortiManager is running 7.2.4. Is there a way to prevent alerts from going out when being logged in from 127.0.0.1?

 

Thanks

1 Solution
hbac
Staff
Staff

Hi @albaker1,

 

I believe you are using automation stitch for admin login alerts. Under Automation Trigger, you can configure Field filter (s) to match specific source IPs or subnets. Wildcard is also supported. For example, you can add a field "Source : 10.0.0.*". Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-wildcard-in-field-filter-in-Automati...

 

Regards, 

View solution in original post

2 REPLIES 2
hbac
Staff
Staff

Hi @albaker1,

 

I believe you are using automation stitch for admin login alerts. Under Automation Trigger, you can configure Field filter (s) to match specific source IPs or subnets. Wildcard is also supported. For example, you can add a field "Source : 10.0.0.*". Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-wildcard-in-field-filter-in-Automati...

 

Regards, 

albaker1
Contributor

Thank you, hbac!

Labels
Top Kudoed Authors