Fortinet white logo
Fortinet white logo

CLI Reference

log alertemail setting

log alertemail setting

Use this command to configure which events will cause the FortiMail send to send an alert email message.

Before the FortiMail system can send an alert email message, you must select the event or events that will cause it to send an alert.

You must also configure alert email message recipients. For more information, see log alertemail recipient.

Syntax

config log alertemail setting

set categories {diskfull ha license-expire queue-over-limit remote-storage-failure sanbox-queue-over-limit spam-queue-over-limit system system-quota-full user-quota-full virus virus-queue-over-limit}

set queue-interval <minutes_int>

set queue-threshold <threshold_int>

set queue-sandbox-threshold <threshold_int>

set queue-spam-outbreak-threshold <threshold_int>

set queue-virus-outbreak-threshold <threshold_int>

set license-interval <days_int>

end

Variable

Description

Default

categories {diskfull
ha
license-expire
queue-over-limit
remote-storage-failure
sanbox-queue-over-limit
spam-queue-over-limit
system
system-quota-full
user-quota-full
virus
virus-queue-over-limit}

Enter a list of one or more of the following event types that will cause alert email:

  • diskfull: The FortiMail system’s hard disk is full.

  • ha: High availability (HA) failover and other events.

    When a FortiMail system is operating in HA mode, the subject line of the alert email includes the hostname <hostname_str> of the cluster member. If you have configured a different host name for each member of the cluster, this lets you identify which system in the HA cluster sent the alert email.

  • license-expire: The FortiGuard license will expire soon.

  • queue-over-limit: The general deferred mail queue has exceeded queue-threshold <threshold_int> during the interval in queue-interval <minutes_int>.

  • remote-storage-failure: Remote archiving or NAS storage has had one or more failures.

  • sanbox-queue-over-limit: The FortiSandbox deferred mail queue has exceeded queue-sandbox-threshold <threshold_int> during the interval in queue-interval <minutes_int>.

  • spam-queue-over-limit: The spam outbreak deferred mail queue has exceeded queue-spam-outbreak-threshold <threshold_int> during the interval in queue-interval <minutes_int>.

  • system: System events such as system errors, system reboot or reload, firmware upgrade or downgrade, and log disk or mail disk formatting.

  • system-quota-full: An email archiving account has exceeded its disk space quota.

  • user-quota-full: An email user’s account has exceeded its disk space quota.

    This setting is available only if the FortiMail system is operating in server mode.

  • virus: The FortiMail system has detected a virus.

  • virus-queue-over-limit: The virus outbreak deferred mail queue has exceeded queue-virus-outbreak-threshold <threshold_int> during the interval in queue-interval <minutes_int>.

system

license-interval <days_int>

Enter how many days before FortiGuard license expiry the FortiMail will send an alert, warning that the license will expire soon. An alert email is also sent on the expiry day. c

30

queue-interval <minutes_int>

Enter the interval in minutes between checks of deferred queue size. Valid range is 10 to 720.

60

queue-sandbox-threshold <threshold_int>

Enter the size that the FortiSandbox deferred email queue must reach to cause an alert email to be sent. Valid range is 10 to 500000.

5000

queue-spam-outbreak-threshold <threshold_int>

Enter the size that the spam outbreak deferred email queue must reach to cause an alert email to be sent. Valid range is 10 to 500000.

5000

queue-threshold <threshold_int>

Enter the size that the general deferred email queue must reach to cause an alert email to be sent. Valid range is 10 to 500000.

5000

queue-virus-outbreak-threshold <threshold_int>

Enter the size that the virus outbreak deferred email queue must reach to cause an alert email to be sent. Valid range is 10 to 500000.

5000

Related topics

log setting remote

log setting local

log alertemail recipient

log alertemail setting

log alertemail setting

Use this command to configure which events will cause the FortiMail send to send an alert email message.

Before the FortiMail system can send an alert email message, you must select the event or events that will cause it to send an alert.

You must also configure alert email message recipients. For more information, see log alertemail recipient.

Syntax

config log alertemail setting

set categories {diskfull ha license-expire queue-over-limit remote-storage-failure sanbox-queue-over-limit spam-queue-over-limit system system-quota-full user-quota-full virus virus-queue-over-limit}

set queue-interval <minutes_int>

set queue-threshold <threshold_int>

set queue-sandbox-threshold <threshold_int>

set queue-spam-outbreak-threshold <threshold_int>

set queue-virus-outbreak-threshold <threshold_int>

set license-interval <days_int>

end

Variable

Description

Default

categories {diskfull
ha
license-expire
queue-over-limit
remote-storage-failure
sanbox-queue-over-limit
spam-queue-over-limit
system
system-quota-full
user-quota-full
virus
virus-queue-over-limit}

Enter a list of one or more of the following event types that will cause alert email:

  • diskfull: The FortiMail system’s hard disk is full.

  • ha: High availability (HA) failover and other events.

    When a FortiMail system is operating in HA mode, the subject line of the alert email includes the hostname <hostname_str> of the cluster member. If you have configured a different host name for each member of the cluster, this lets you identify which system in the HA cluster sent the alert email.

  • license-expire: The FortiGuard license will expire soon.

  • queue-over-limit: The general deferred mail queue has exceeded queue-threshold <threshold_int> during the interval in queue-interval <minutes_int>.

  • remote-storage-failure: Remote archiving or NAS storage has had one or more failures.

  • sanbox-queue-over-limit: The FortiSandbox deferred mail queue has exceeded queue-sandbox-threshold <threshold_int> during the interval in queue-interval <minutes_int>.

  • spam-queue-over-limit: The spam outbreak deferred mail queue has exceeded queue-spam-outbreak-threshold <threshold_int> during the interval in queue-interval <minutes_int>.

  • system: System events such as system errors, system reboot or reload, firmware upgrade or downgrade, and log disk or mail disk formatting.

  • system-quota-full: An email archiving account has exceeded its disk space quota.

  • user-quota-full: An email user’s account has exceeded its disk space quota.

    This setting is available only if the FortiMail system is operating in server mode.

  • virus: The FortiMail system has detected a virus.

  • virus-queue-over-limit: The virus outbreak deferred mail queue has exceeded queue-virus-outbreak-threshold <threshold_int> during the interval in queue-interval <minutes_int>.

system

license-interval <days_int>

Enter how many days before FortiGuard license expiry the FortiMail will send an alert, warning that the license will expire soon. An alert email is also sent on the expiry day. c

30

queue-interval <minutes_int>

Enter the interval in minutes between checks of deferred queue size. Valid range is 10 to 720.

60

queue-sandbox-threshold <threshold_int>

Enter the size that the FortiSandbox deferred email queue must reach to cause an alert email to be sent. Valid range is 10 to 500000.

5000

queue-spam-outbreak-threshold <threshold_int>

Enter the size that the spam outbreak deferred email queue must reach to cause an alert email to be sent. Valid range is 10 to 500000.

5000

queue-threshold <threshold_int>

Enter the size that the general deferred email queue must reach to cause an alert email to be sent. Valid range is 10 to 500000.

5000

queue-virus-outbreak-threshold <threshold_int>

Enter the size that the virus outbreak deferred email queue must reach to cause an alert email to be sent. Valid range is 10 to 500000.

5000

Related topics

log setting remote

log setting local

log alertemail recipient