<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint Alerts in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Alerts/m-p/179728#M6955</link>
    <description>&lt;P&gt;So I have a real beef with Endpoint alerts. Presently looking in the Infinity Portal I can set alerts&lt;/P&gt;
&lt;P&gt;based on a number of criteria. One such criteria is 'The computer is infected.'&lt;/P&gt;
&lt;P&gt;Now for configuration of this alert I can set 'Trigger alert when the condition affects' with a setting&lt;/P&gt;
&lt;P&gt;to set the number of infected devices to trigger an alert. Unfortunately the minimum setting is 10.&lt;/P&gt;
&lt;P&gt;Now I don't know about you but I want to know immediately if someone is infected.&lt;/P&gt;
&lt;P&gt;Worse, I have 10 employees so what you are really saying is, 'Ah it's okay there's only 10 infections...&lt;/P&gt;
&lt;P&gt;Hmmm, it's our entire organization.&lt;/P&gt;
&lt;P&gt;Now I can set it using percentage 10% which would be 1, but it's a very odd choice to stop at 10 devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 May 2023 16:08:36 GMT</pubDate>
    <dc:creator>Tony_Graham</dc:creator>
    <dc:date>2023-05-02T16:08:36Z</dc:date>
    <item>
      <title>Endpoint Alerts</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Alerts/m-p/179728#M6955</link>
      <description>&lt;P&gt;So I have a real beef with Endpoint alerts. Presently looking in the Infinity Portal I can set alerts&lt;/P&gt;
&lt;P&gt;based on a number of criteria. One such criteria is 'The computer is infected.'&lt;/P&gt;
&lt;P&gt;Now for configuration of this alert I can set 'Trigger alert when the condition affects' with a setting&lt;/P&gt;
&lt;P&gt;to set the number of infected devices to trigger an alert. Unfortunately the minimum setting is 10.&lt;/P&gt;
&lt;P&gt;Now I don't know about you but I want to know immediately if someone is infected.&lt;/P&gt;
&lt;P&gt;Worse, I have 10 employees so what you are really saying is, 'Ah it's okay there's only 10 infections...&lt;/P&gt;
&lt;P&gt;Hmmm, it's our entire organization.&lt;/P&gt;
&lt;P&gt;Now I can set it using percentage 10% which would be 1, but it's a very odd choice to stop at 10 devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 16:08:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Alerts/m-p/179728#M6955</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2023-05-02T16:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Alerts</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Alerts/m-p/179764#M6956</link>
      <description>&lt;P&gt;Hi Tony,&lt;/P&gt;
&lt;P&gt;Would recommend further exploring the Threat Hunting queries, which you can bookmark and set notifications for.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Login to Infinity Portal, navigate to Harmony Endpoint and the Threat Hunting section.&lt;/LI&gt;
&lt;LI&gt;In the search/query area, change Process to Detection Event.&lt;/LI&gt;
&lt;LI&gt;Click on the Plus icon and add:&lt;BR /&gt;a. Detection: Attack Status = Exists&lt;BR /&gt;b. Detection: Triggered By IS Endpoint Anti-Ransomware&lt;/LI&gt;
&lt;LI&gt;Click on the “Star” icon to bookmark the query for repeat/future use.&lt;/LI&gt;
&lt;LI&gt;Fill in the details of Name and Importance and place a check mark in the “Send Email Notification” box.&lt;/LI&gt;
&lt;LI&gt;Note the tag name will allow grouping of bookmarks within the menu section. This is optional.&lt;/LI&gt;
&lt;LI&gt;By default alert notifications are sent every hour, on the hour. Shortly after the top of the hour, the admins of the portal should get an email alert based on the query bookmarked.&lt;/LI&gt;
&lt;LI&gt;To check/review the notification settings click the three dot icon next to the query bar and navigate to notifications.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 12:17:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Alerts/m-p/179764#M6956</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-05-03T12:17:40Z</dc:date>
    </item>
  </channel>
</rss>

