Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ChrisMartel
Employee
Employee

SmartEvent IPS alert example

Hey guys,

 

I'm trying to set up an email alert for every IPS log with action prevent and severity critical. I'm not having any luck. Can someone provide an example of an IPS alert that they have set up through SmartEvent? I'm currently on R80.40 latest ongoing.

 

I've had a little bit of luck getting emails with some correlated logs but they don't show any valuable information (no attack name, action etc..) even after enabling the column in "Event Format" and lumping them into the same event in the "Count logs" section. I have been testing by just using IPS action = Prevent for right now. Also note that the single log events wont trigger an email only the correlated. Is there something I'm missing? Pictures below. Thanks!!

 

1.JPG2.JPG3.JPG

8 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events