Fortinet white logo
Fortinet white logo

FortiDLP Administration Guide

Migrating to incident notifications from SMTP incident email alerts

Migrating to incident notifications from SMTP incident email alerts

FortiDLP's email service for customers with on-premises SMTP servers will be deprecated by September. If you are currently using this functionality and would like to migrate to FortiDLP's new cloud SMTP service that allows you to receive incident notifications via email, follow these steps.

How to migrate to incident notifications from incident email alerts
  1. Follow the steps in Creating incident notification subscriptions to create any needed incident notification subscriptions. Detections are not supported, but you can use webhooks or SIEM tools to be notified of detections (see Webhooks and SIEM tools).
  2. Tooltip

    We recommend initially creating all of the required notification subscriptions with the Enabled toggle off to avoid getting duplicate emails.

  3. Follow the steps in Editing incident notification subscriptions for each notification you want to receive, turning the Enabled toggle on and saving the configuration. Then, at the bottom of the panel, click Send to send a verification email to each recipient. You can confirm a subscription has been enabled and verified in the Incident notifications table.

  4. Follow the steps in Deleting SMTP email alerts (deprecated) to delete old email alert configurations.

Migrating to incident notifications from SMTP incident email alerts

Migrating to incident notifications from SMTP incident email alerts

FortiDLP's email service for customers with on-premises SMTP servers will be deprecated by September. If you are currently using this functionality and would like to migrate to FortiDLP's new cloud SMTP service that allows you to receive incident notifications via email, follow these steps.

How to migrate to incident notifications from incident email alerts
  1. Follow the steps in Creating incident notification subscriptions to create any needed incident notification subscriptions. Detections are not supported, but you can use webhooks or SIEM tools to be notified of detections (see Webhooks and SIEM tools).
  2. Tooltip

    We recommend initially creating all of the required notification subscriptions with the Enabled toggle off to avoid getting duplicate emails.

  3. Follow the steps in Editing incident notification subscriptions for each notification you want to receive, turning the Enabled toggle on and saving the configuration. Then, at the bottom of the panel, click Send to send a verification email to each recipient. You can confirm a subscription has been enabled and verified in the Incident notifications table.

  4. Follow the steps in Deleting SMTP email alerts (deprecated) to delete old email alert configurations.