Prerequisite:
You must identify a mail server for email notifications in the E-mail page (Manager → <Admin Domain Name> → Setup → Notification → IPS Events → E-mail).
Users can be alerted by email or pager when an alert is generated that matches a chosen severity or customized attack setting.
The procedure for configuring email alerts is described here. The procedure for configuring pager is similar.
Steps:
Select Manager → <Admin Domain Name> → Setup → Notification → IPS Events → E-mail.
The E-Mail and Recipient List information is displayed under the E-mail tab.
.png)
Specify your options in the corresponding fields.
Field
Description
Enable E-mail Notification
Select Yes to enable alert notification through email.
Send Notification If
The attack definition has this notification option explicitly enabled — Send notification for attacks that match customized policy notification settings, which you must set when editing attack responses within the policy editor.
The following notification filter is matched — Send notification based on the following filters:
Severity Informational and above — Includes all alerts
Severity Low and above — Includes low, medium, and high severity alerts
Severity Medium and above — Includes both medium and high severity alerts
Severity High — Includes only high severity alerts
The table below explains the functional interdependency of the two options.
Suppression Time
Type a Suppression Time for the notification. The suppression time is the duration (minutes and seconds) to wait after an alert notification has been sent before sending another alert notification. The default and minimum value is 10 minutes and 0 seconds. Suppression time is useful to avoid sending excessive notifications when there is heavy attack traffic.
Message Body
The message body is a preset response sent with the notification with information pertaining to the alert.
System Default — The system default message provides the notified admin with the most basic attack details so that an immediate response can be made. Details include the attack name, time detected, attack type, severity, the Sensor interface where detected, and the source and/or destination IP addresses.
Note
You cannot edit the System Default message.
Customized — Select Customized against Message Body and click Edit to view the Custom Message page.
You can type custom text in the Subject field or Body section, as well as click one or more of the provided variable links at Subject Line Variables or Content-Specific Variables.
Note
Prior to Sensor software version 10.1.5.116, the variables $IV_MALWARE_FILE_SHA1_HASH$ and $IV_MALWARE_FILE_SHA256_HASH$ do not display the file hashes.
Notification option explicitly enabled
Notification filter is matched
Functionality
✔
Emails are sent only for the attacks where the notification option is enabled.
✔
Emails are sent only when the defined severity level is matched and the notification option is disabled.
✔
✔
If the attack matches at least one of the criteria, an email is sent.
Click Save to return to the email or pager notification settings page.
Click
in the Recipient List section of the E-mail page.The Add a Recipient page is displayed.
Enter the Recipient email address in the SMTP Address field and click Save.
The email address is listed under the Recipient List on the E-mail tab.
You can configure pager settings using a similar procedure in the Pager page. Select Manager → <Admin Domain Name> → Setup → Notification → IPS Events → Pager to view the Pager page.
Email and pager notifications are configured per admin domain.