Hey,
To avoid misconfiguration of events I recommend using the existing event for "Generic IPS Event" under "Legacy" folder.
The correlated event information displayed is already defined and supposed to contain relevant information.
Try not to add too many conditions at once, change it one by one and see that the last event definitions worked as expected.
a) First try to only change action to "Prevent" from "Control"
b) Add email reaction and see that it contains all relevant information that you require.
c) Add severity by clicking show more fields -> Existing fields -> Severity -> Critical
d) Add "Accumulate additional logs..."
Tell me if that helps you.
Amir Senn
Kind regards, Amir Senn