Management General Management Topics Logging and Reporting Multi-Domain Management Policy Management
- Local User Groups
AI & Machine Learning
I need to configure email notification when critical event is appeared in logs. An email alert must send to administrator mail box when certain IPS protection is appeared in logs. I configuring SmartEvent for this task. An email alert is added in "Objects" -> "Automatic Reactions". Now i configured an alert for certain Firewall blade log (when someone tryng to get access to port 443 of certain IP external IP address, screenshot in attach) and this alert is working.
I configured an alert for Action: Detect (IPS blade) but there is no result (screenshot in attach).
There is default entry in "Global Exclusions" (screenshot in attach).
When this record is disabled, notifications about different events that I do not need are sends to my email address.
FYI you can insert graphics inline (not as attachments).
Makes it easier to follow.
First off can you confirm version/jumbo hotfix level?
Looks like R80.10 from screenshots.
Also, when you make said changes, did you push the Event policy?
This is required anytime changes are made.
I assume the default exclusion is there for a reason.
Thank you for your answer.
Smart Event 80.10 jumbo hotfix Take 70
Security Management Server 80.10 jumbo hotfix Take 42.
Yes, i install policy on Smart Event after make changes.
Yes, i returned default exclusions to the initial state.
2 things I would like to add here.