fenotify rsyslog trap-sink <sink_name> prefer message delivery

Prev Next

Selects the default delivery schedule for rsyslog notifications.

Syntax

[no] fenotify rsyslog trap-sink <sink_name> prefer message delivery <delivery_method>

Parameters

no

Disables rsyslog notification trap sinks.

sink_name

The name of the rsyslog notification trap sink.

delivery_method

The following default delivery schedules are supported:

  • per-event—Information about each event, sent when the event is triggered.

  • daily-per-source—Information about all events detected in the past 24 hours, with one notification sent for each source IP.

  • hourly-per-source—Information about all events detected in the past hour, with one notification sent for each attacker (source).

  • per-1min-per-source—Information about all events detected in the past minute, with one notification sent for each source IP.

  • per-5min-per-source—Information about all events detected in the past 5 minutes, with one notification sent for each source IP.

Example

The following example selects information delivered about each event, sent when the event is triggered:

hostname (config) # fenotify rsyslog trap-sink rk prefer message delivery per-event

User role

Admin and Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Before release 7.6

  • Endpoint Security (HX): Release 3.5.0

  • File Protect: Before release 7.6

  • Malware Analysis: Before release 7.6

  • Network Security: Before release 7.6