To set up the SMTP recipients, perform the following subtasks:
Add the SMTP recipients.
Configure the SMTP recipient listing for email notifications,
Go to CLI configuration mode:
hostname > enablehostname # configure terminalEnable email notifications:
hostname (config) # fenotify email enableAdd a recipient for email notifications:
hostname (config) # fenotify email recipient <rname>Select a recipient to receive email notifications (one recipient per command):
hostname (config) # fenotify email recipient <rname> enableSpecify the email address for a recipient who will receive email notifications:
hostname (config) # fenotify email recipient <rname> email-address <email_address>Save the configuration:
hostname (config) # write memory
Go to CLI configuration mode:
hostname > enablehostname # configure terminalEnable email notifications:
hostname (config) # fenotify email enableTo send notifications in JSON Normal format containing detailed information and abstracts such as alert type, ID, source IP, malware name, hostname, and alert URL without any redundant information, enter:
hostname (config) # fenotify email recipient <rname> prefer message format json-normalSpecify how email notifications are delivered to the specified recipient:
To deliver the notification as an email attachment, enter:
hostname (config) # fenotify email recipient rname prefer message send-as attachmentTo deliver the notification in the email body (the default), enter:
hostname (config) # fenotify email recipient rname prefer message send-as in-line
Select the event type:
hostname (config) # fenotify email alert indicator-presence enablehostname (config) # fenotify email alert indicator-executed enablehostname (config) # fenotify email alert exploit-detected enablehostname (config) # fenotify email alert exploit-blocked enablehostname (config) # fenotify email alert malware-object enableSave the configuration:
hostname (config) # write memory