Fortinet white logo
Fortinet white logo

User Guide

Email notifications

Email notifications

Receive an email notification when a detector triggers a detection. Notifications are configured and applied on a per-user basis using the email address tied to a user's account. If you are logging in for the first time or have never updated your notifications, you will see the Default Notification created for every user.

The Email Notifications page displays the notifications for the account. You can filter the page by Email Type (Assigned Detections or New Detections) and by Status (All, Enabled, or Disabled).

To create a notification:
  1. In the toolbar, click the gear icon and select Email Notifications. The Notifications page opens.
  2. Click the Create Notification button at the top right-side of the page. The Create a New Notification dialog opens.

  3. Enter the Notification Name.
  4. From the Account dropdown, select an account.
  5. Select the Detection Type.
    • Assigned Detections: Select to send an email notification to the user the detection is assigned to.
    • New Detections: Select to create and configure a new notification.
  6. Configure the new notification:

    Severities

    Select one of the following:

    SeverityDescriptionExamples
    HighSignificant to fair impact with the potential to spread or escalateMalicious code execution, C2 communications, lateral movement, data exfiltration
    ModerateFair impact with minimal potential to spread or escalateActivity that could indicate malicious intent, untargeted attacks with unknown success, data leakage, subversion of security or monitoring tools
    LowLittle to no impact expectedPotentially unauthorized software, devices, or resource use, untargeted adware or spyware, compromise of a personal device or device on an untrusted network, insecure configurations
    Confidences

    Select one of the following:

    ConfidenceMinimum True-Positive Rate
    High90%
    Moderate75%
    Low50%
    Categories

    Select a category from the list. For information, see Detections > Detector Categories.

    Email Type
    • Individual: Sends an email for each individual detector that becomes active.

    • Digest: Sends you a single email each day at the specified time (default 08:00 Eastern) summarizing detectors that became active and/or were resolved during the previous day.

      Select Include Resolved Details to include detection resolution information in the email The Email Notifications page will display Digest with Resolve Details next to the email when enabled.

  7. Click Create.
To edit a notification:
  1. Click the Actions menu at right side of the notification.

  2. Click Edit Notification . The Edit Notification dialog opens.
  3. Edit the notification details and click Save.
To delete or disable a notification:
  1. Click the Actions menu at right side of the notification.
  2. Click Delete Notification or Disable Notification. A confirmation dialog opens.
  3. Click Confirm.

Email notifications

Email notifications

Receive an email notification when a detector triggers a detection. Notifications are configured and applied on a per-user basis using the email address tied to a user's account. If you are logging in for the first time or have never updated your notifications, you will see the Default Notification created for every user.

The Email Notifications page displays the notifications for the account. You can filter the page by Email Type (Assigned Detections or New Detections) and by Status (All, Enabled, or Disabled).

To create a notification:
  1. In the toolbar, click the gear icon and select Email Notifications. The Notifications page opens.
  2. Click the Create Notification button at the top right-side of the page. The Create a New Notification dialog opens.

  3. Enter the Notification Name.
  4. From the Account dropdown, select an account.
  5. Select the Detection Type.
    • Assigned Detections: Select to send an email notification to the user the detection is assigned to.
    • New Detections: Select to create and configure a new notification.
  6. Configure the new notification:

    Severities

    Select one of the following:

    SeverityDescriptionExamples
    HighSignificant to fair impact with the potential to spread or escalateMalicious code execution, C2 communications, lateral movement, data exfiltration
    ModerateFair impact with minimal potential to spread or escalateActivity that could indicate malicious intent, untargeted attacks with unknown success, data leakage, subversion of security or monitoring tools
    LowLittle to no impact expectedPotentially unauthorized software, devices, or resource use, untargeted adware or spyware, compromise of a personal device or device on an untrusted network, insecure configurations
    Confidences

    Select one of the following:

    ConfidenceMinimum True-Positive Rate
    High90%
    Moderate75%
    Low50%
    Categories

    Select a category from the list. For information, see Detections > Detector Categories.

    Email Type
    • Individual: Sends an email for each individual detector that becomes active.

    • Digest: Sends you a single email each day at the specified time (default 08:00 Eastern) summarizing detectors that became active and/or were resolved during the previous day.

      Select Include Resolved Details to include detection resolution information in the email The Email Notifications page will display Digest with Resolve Details next to the email when enabled.

  7. Click Create.
To edit a notification:
  1. Click the Actions menu at right side of the notification.

  2. Click Edit Notification . The Edit Notification dialog opens.
  3. Edit the notification details and click Save.
To delete or disable a notification:
  1. Click the Actions menu at right side of the notification.
  2. Click Delete Notification or Disable Notification. A confirmation dialog opens.
  3. Click Confirm.