- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: SmartEvent email notifications
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SmartEvent email notifications
I need to configure email notification when critical event is appeared in logs. An email alert must send to administrator mail box when certain IPS protection is appeared in logs. I configuring SmartEvent for this task. An email alert is added in "Objects" -> "Automatic Reactions". Now i configured an alert for certain Firewall blade log (when someone tryng to get access to port 443 of certain IP external IP address, screenshot in attach) and this alert is working.
I configured an alert for Action: Detect (IPS blade) but there is no result (screenshot in attach).
There is default entry in "Global Exclusions" (screenshot in attach).
When this record is disabled, notifications about different events that I do not need are sends to my email address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FYI you can insert graphics inline (not as attachments).
Makes it easier to follow.
First off can you confirm version/jumbo hotfix level?
Looks like R80.10 from screenshots.
Also, when you make said changes, did you push the Event policy?
This is required anytime changes are made.
I assume the default exclusion is there for a reason.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for your answer.
Smart Event 80.10 jumbo hotfix Take 70
Security Management Server 80.10 jumbo hotfix Take 42.
Yes, i install policy on Smart Event after make changes.
Yes, i returned default exclusions to the initial state.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you show a log or two that should have matched this?
(Feel free to mask sensitive data)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Example notificatinon:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I recommend having TAC take a look at this, because that should catch it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 things I would like to add here.
- Make sure you use the latest Jumbo Hotfix for Smart Event. There is so much more fixed that is not explicitly listed in the fix list. (I had too many TAC cases on SmartEvent 😉
- Be aware that if email delivery becomes a problem it will result in some additional issues on SmartEvent. So make sure you don't have a spam filter getting in the way. (Valueable lesson from said TAC cases.)
