I need to configure email notification when critical event is appeared in logs. An email alert must send to administrator mail box when certain IPS protection is appeared in logs. I configuring SmartEvent for this task. An email alert is added in "Objects" -> "Automatic Reactions". Now i configured an alert for certain Firewall blade log (when someone tryng to get access to port 443 of certain IP external IP address, screenshot in attach) and this alert is working.
I configured an alert for Action: Detect (IPS blade) but there is no result (screenshot in attach).
There is default entry in "Global Exclusions" (screenshot in attach).
When this record is disabled, notifications about different events that I do not need are sends to my email address.