Create alarms based on health monitor events, which can then generate a Health Monitor Event Summary report.
Review available health monitor signature IDs.
From the Trellix ESM dashboard, click
and select More Settings.On the system navigation tree, select Trellix ESM and click
.Click Alarms.
Note
The number of events is limited to 10 for Internal Event Match alarms.
Set up an alarm before a health monitor event is generated:
Set up an alarm Condition with the Internal Event Match type.
On the Field line, select Signature ID.
In the Values field, enter the signature ID for the health monitor rules.
Enter the remaining settings for the alarm.
Set up an alarm if a health monitor event exists:
On the system navigation tree, click
.Select a view that displays the health monitor event (Event Analysis or Default Summary).
Click the event then click
.Select → .
The Alarm Managementpage opens. For more information, see Create alarm.