Hi Valeri, can you elaborate a bit? What do you mean by custom alert in the logs please? Probably, I was not clear when I said initially I am creating a custom alert script. What I meant by this is just:
1. In global properties ->Logs and Alert->Alerts to check out the "Run UserDefined script" /path/to/the/script
2. Put the script ( the one I mentioned earlier in my initial post ) to $FWDIR/bin directory
3. In Threat Prevention Policy ( for the rule I'd like to send the alerts from ) check out the Track option 'User Alert'
I tested this procedure with the Single Mgmt server in my Lab and it works
Are we on the same page?
Thanks