Hi Jay,
Can you confirm if you have configured your Fortigate device to send syslogs to LEM? The CSV file only contains events from Windows Security logs.
You will need to send syslogs from the firewall to LEM. LEM can then capture events to show that someone logged onto the device & made a change (assuming your devices generate this information, but most devices do). Once the logging is setup, we can then create a rule to trigger an alert.
If you would like a call to assist with the above let me know & we can arrange something. Also, if network device backup & config is of interest, you could check out our Network Configuration Manager.
Jamie