To configure when IPS event notifications are delivered, use the fenotify preferences ips‑delivery‑mode command in configuration mode. This command applies only to IPS-enabled appliances on which you have enabled IPS event notifications services and configured IPS event notification methods.
Syntax
fenotify preferences ops-delivery-mode <mode>
User role
Admin or Operator
Supported appliances
Command introduced in Release 7.5.0 for IPS-enabled appliances only.
Description
Configures when IPS event notifications are delivered. For more information, see the Network Security IPS Feature Guide.
Parameters
mode
Specify the delivery mode for IPS event notifications:
instant—Send only when an IPS event is detected. This is the default value.confirmation—Send only when an attack has been confirmed (either positive or negative).dual—Send both when an IPS event is detected and when an attack has been confirmed.
By default, the system is configured to use instant delivery mode, which is useful in an organization that archives notifications and then filters and analyzes the information later. When you first activate IPS features, we recommend that you use dual mode so that you see both detection and confirmation of IPS events. If your organization does not archive the volume of notifications generated in this mode, you can decrease the volume of notifications by using confirmation mode.
Example
hostname (config) # fenotify preferences ips dual