Fault provides information about the current status of your Trellix IPS installation. Fault notification can be configured based on the severity of a fault.
A complete list of faults is available in the %programfiles%\Trellix\IPS Manager\App\config\FaultNameAndText.properties file.
You can use the following methods to forward fault information:
- SNMP traps
- Syslog
- Scripts
- Pager
If you are parsing fault notifications, it is recommended that you customize the notification that suits your needs.
Note
Default fault notification format may change in newer releases of the Manager.
The following table details the methods to forward fault information.
| Method | Information |
|---|---|
| SNMP traps | You need the following to configure the Manager to send SNMP traps:
|
| Syslog | You can configure the Manager to notify syslog servers for alerts, system faults, Firewall access rule matches, and user-activity audit for the Manager. If you enable syslog notification for Firewall access rules, and if you have enabled Firewall access rules logging per Sensor, the Manager sends a syslog message to the configured syslog server for each connection attempt matching an rule. This enables you to track your users' connection attempts and the results.
You need the following to configure the Manager to forward syslog messages:
Configuring syslog notification involves the following steps:
|
| Email and pager | You can configure the Manager to do the following:
Note the following:
Configuring email notification involves the following steps:
|
| Scripts | Scripts are useful for complex integrations. Scripts are a sequence of commands that can use template variables. The Manager replaces these variables with the relevant values before executing the command. For example, you can use scripts to extract information from the alerts and send customized emails for specific conditions.
Scripts can invoke another batch file and provide variables as command line parameters for the invoked program. For more information, refer to Trellix Intrusion Prevention System Product Guide. Also see the Readme.doc at %programfiles%\Trellix\IPS Manager\App\diag\AlertNotificationScript |
| Suppression | While configuring some of the notification methods, you can specify the suppression time value. Suppression time is the time (minutes and seconds) the Manager should wait after an alert notification has been sent before sending another alert notification. The default and minimum value is 10 minutes. Suppression time is useful to avoid sending excessive notifications when there is heavy attack traffic.
The specify suppression time value for the following notification methods:
Suppression time value does not apply to syslog and SNMP. All events are forwarded. |