FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
tnaik
Staff
Staff
Article Id 190399

Description

 

This article describes how to create an event handler in FortiAnalzyer for Policy change in FortiGate.

Solution

 

  1. Create a mail server.

    Login to FortiAnalyzer go to System setting -> Mail Server and select 'Create new'.

    Now enter the mail server details.


 
 
  1. Test email server working status.

    Select  'Mail Server' and select the mail server created in step 1. Now select 'Test'.

    A notification message pops up immediately on the same page.
     
     
     
     
     
  2. Login to Fortianalyzer go to Incident and Event ->Event Handler list and select 'Create New'.

    Enter the details below:
      
     
     
    Now on the same page enter the notification details:
     
    To: destination email address.
     
    From: source email address which is present in the mail server.
     
    Mail Server: created in Step 1.
     
     
     
     
    Test.

    Try to change any policy in FortiGate that receives email notifications on the email address mentioned.
     
Related Articles: