Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
veejay
New Contributor

DLP Email Alerts

Does anyone know if it is possible to setup email alerts for DLP logs on Fortigate 5.2?  From what I can see there isn't a pre-baked option.  Is it possible to setup customized alerts from the CLI?

6 REPLIES 6
AndreaSoliva
Contributor III

Hi

 

for email alerting following can be configured (no possibility for DLP):

 

config alertemail setting set username <user-name_str> set mailto1 <email-address_str> set mailto2 <email-address_str> set mailto3 <email-address_str> set filter-mode {category | threshold} set email-interval <minutes_int> set emergency-interval <minutes_int> set alert-interval <minutes_int> set critical-interval <minutes_int> set error-interval <minutes_int> set warning-interval <minutes_int> set notification-interval <minutes_int> set information-interval <minutes_int> set debug-interval <minutes_int> set severity {alert | critical | debug | emergency | error | information | notification | warning} set IPS-logs {disable | enable} set firewall-authentication-failure-logs {disable | enable} set HA-logs {enable | disable} set IPsec-error-logs {disable | enable} set FDS-update-logs {disable | enable} set PPP-errors-logs {disable | enable} set sslvpn-authentication-errors-logs {disable | enable} set antivirus-logs {disable | enable} set webfilter-logs {disable | enable} set configuration-changes-logs {disable | enable} set violation-traffic-logs {disable | enable} set admin-login-logs {disable | enable} set local-disk-usage-warning {disable | enable} set FDS-license-expiring-warning {disable | enable} set FDS-license-expiring-days <days_int> set local-disk-usage <percentage> set fortiguard-log-quota-warning {disable | enable} end

 

the only thing you can do from my perspective is: if you deliver your logs to a FortiAnalyzer you can filter there the logs based on a event and if this event happens (information for DLP in the logs) a mail is send out to informe regarding this event.

 

On the FortiGate itself I do not see any possibility.

 

have fun...

 

Andrea

veejay
New Contributor

I liked Andrea's suggestion of using FortiAnalyzer but it's kind of overkill for my use case.  In the end, I just setup Syslog and I have an alert for dlp messages.  It'd be great if they introduce email logs for dlp directly in the product but this will work for now.

ikoimecs
New Contributor II

Year 2017, July 5th, FortiOS v5.6 - still no alerts for DLP !!!

nojeffrey

Year 2018, Feb 8th, FortiOS v5.6.3 - still no alerts for DLP !!!

 

Fullmoon

maybe this is one of the minor feature/s that fortinet development could address :)

Fortigate Newbie

Fortigate Newbie
robdog
New Contributor II

They wont address it because you can do it in Fortianalyser... money money moneh !!

Labels
Top Kudoed Authors