Event notifications

Prev Next

As described in Managing the distribution of alert notifications, you can configure alert notifications for the Central Management System appliances, for managed appliances, or both.

Alert Type

Description

exploit-blocked

Includes exploits that have been blocked by Exploit Guard.

exploit-detected

Includes exploits that have only been detected by Exploit Guard. This does not include exploits that have also been blocked.

indicator-executed

Includes only indicators that have executed.

indicator-presence

Includes indicators that are present in the environment, including those that have executed.

malware-object

Includes malware objects that have been detected by Signature and Heuristic Detection or MalwareGuard.

You can send a test-fire notification from the Central Management System appliance or from managed appliances. There are the following differences:

  • A test-fire notification sent from a managed appliance contains more information than one sent from the Central Management System appliance.

  • Notifications sent from the Central Management System appliance do not appear in the Central Management System database or Web UI.

  • Notifications sent from a managed appliance do appear in the appliance database and Web UI; if they are aggregated up to the Central Management System appliance, they also appear in the Central Management System database and Web UI.

  • After notifications are aggregated up to the Central Management System appliance, another notification is sent from the Central Management System appliance.

Note

This section describes how to configure event (alert) notifications. See Configuring system email settings for information about system email notifications.