Enabling SMTP email alerts (deprecated)
To enable an email alert, follow these steps.
How to enable an email alert
- In the FortiDLP Console, on the left-hand sidebar, click
.
- Click SMTP.
- In the Simple Mail Transfer Protocol (SMTP) config section, do the following:
- In the Host field, type the hostname of the SMTP server.
- In the Port field, type the port number of the SMTP server.
- In the From address field, type an email address to display in the sender field of alerts.
- In the From name field, type a name to display in the sender field of alerts. For example,
FortiDLP. - Optionally, if your SMTP host requires authentication:
- In the Username field, type the username of the SMTP email account.

For Microsoft 365 configurations, the Username must be set to the same value as the From address. - In the Password field, type the password of the SMTP email account.

Microsoft 365 and Gmail require an application-specific password to be used if two-factor authentication (2FA) is enabled. For more information, refer to the Microsoft 365 and Gmail documentation.
- Click Save.

For example,
noreply@example.com. - Click Create new email alert.
- In the Create new email alert dialog box, do the following:
- In the To address field, type the email address to send alerts to.
- In the Subject field, type a string to display in the subject line of alerts.
- In the Event type menu, do one of the following:
- To be notified of detections:
- In the Event type menu, select Detection.
- Optionally, to apply filters:
- In the Tags field, type one or more tags to filter by, separated by a space.
- In the Filter type menu:
- To be notified of detections that have any of the chosen tags, select Any tag.
- To be notified of detections that have all of the chosen tags, select All tags.
- In the Minimum risk score field, type a minimum risk score between 0–100 to filter by.
- To be notified of incidents:
- In the Event type menu, select Incident.
- Turn the relevant toggles on to be notified when:
- An incident is created
- An incident is deactivated
- A detection is generated by a new user (for an incident)
- A detection is generated by a new node (for an incident).
- Optionally, in the Minimum risk score field, type a minimum risk score between 0–100 to filter by.
- To be notified of detections:
- Optionally, in the Token replenish rate per hour field, type a number to limit the rate at which alerts are sent.
- Optionally, in the Max tokens field, type a value to limit the number of alerts sent, considering the Token replenish rate per hour.
- Click Create.

For example, setting this field to
60would enable email alerts to be sent no more than once per minute. Leaving the default value of0would allow email alerts to be sent each time a detection/incident occurs.
For example, setting this field to
10and the Token replenish rate per hour to60would enable FortiDLP to send no more than 10 email alerts at once (in a burst), and no more than one email alert per minute on average. - Optionally, to test the configuration:
- Click the table row of the email alert you enabled.
- At the bottom of the panel, click Send.
To create multiple email alerts, repeat steps 4–6.