- CheckMates
- :
- Products
- :
- General Topics
- :
- How to send a Security Alert from Smart-1
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to send a Security Alert from Smart-1
Hello ALL
I understand from reading SK25941 and other resources that email alerts can be sent using methods like SmartEvent or SmartDashboard.
However, is it possible to send alerts detected by Threat Prevention on Smart-1 to chat tools like Microsoft Teams?
Thank You in Advance
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Explore Infinity Playblocks for this type of requirement.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, this uses sendmail.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Explore Infinity Playblocks for this type of requirement.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In the Threat Prevention policy, you can set the Track field to something other than Log (e.g. Alert).
Those log types can execute a script, which must exist on the management.
You specify the full path to the script in Global Properties:
For an example script, see: https://community.checkpoint.com/t5/Management/SmartEvent-External-Script-for-Mail/m-p/78994
It references SmartEvent here, but the script format is the same.
Or, as @Chris_Atkinson said, look at Infinity Playblocks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Indeed, Playblocks has Teams and Slack integration.
Very soon, we'll add customization for playbooks that will allow you to further customize on which specific events you want to alert.
