Fortinet white logo
Fortinet white logo
25.1.a

Adding a policy

Adding a policy

Add a policy rule to associate the query with the channel.

To add a policy rule:
  1. Go to Alerts > Policy Rules.

  2. Click ADD RULE.

  3. In the Rule Name field, enter a name for the rule.

  4. In the Rule Notes field, enter a description for the rule.

  5. If you selected All Organizations in the Organization dropdown list at the top of the GUI, you can select which organization that the rule will belong to.

  6. If you want the rule to be active, select the Enable Rule checkbox.

  7. In the Event Type dropdown list, select Asset, Service, Software, Vulnerability, Detector, or Scan.

  8. In the Event Name dropdown list, select the event.

  9. In the Level dropdown list, select Notice, Warning, or Critical.

  10. In the Channel Name dropdown list, select the channel.

  11. In the Channel Notes field, enter a description of the channel.

  12. In the Query Name dropdown list, select the query.

  13. In the Query Notes field, enter a description of the query.

  14. If the Criteria dropdown list is displayed, select equal, greater, less, greater_equal, or less_equal.

  15. If the Threshold Count field is displayed, enter the number of times the criterion is matched before the alert is triggered.

  16. Click Save.

Adding a policy

Adding a policy

Add a policy rule to associate the query with the channel.

To add a policy rule:
  1. Go to Alerts > Policy Rules.

  2. Click ADD RULE.

  3. In the Rule Name field, enter a name for the rule.

  4. In the Rule Notes field, enter a description for the rule.

  5. If you selected All Organizations in the Organization dropdown list at the top of the GUI, you can select which organization that the rule will belong to.

  6. If you want the rule to be active, select the Enable Rule checkbox.

  7. In the Event Type dropdown list, select Asset, Service, Software, Vulnerability, Detector, or Scan.

  8. In the Event Name dropdown list, select the event.

  9. In the Level dropdown list, select Notice, Warning, or Critical.

  10. In the Channel Name dropdown list, select the channel.

  11. In the Channel Notes field, enter a description of the channel.

  12. In the Query Name dropdown list, select the query.

  13. In the Query Notes field, enter a description of the query.

  14. If the Criteria dropdown list is displayed, select equal, greater, less, greater_equal, or less_equal.

  15. If the Threshold Count field is displayed, enter the number of times the criterion is matched before the alert is triggered.

  16. Click Save.