As described in Managing the distribution of alert notifications, you can configure alert notifications for the Central Management System appliances, for managed appliances, or both.
Alert Type | Description |
|---|---|
exploit-blocked | Includes exploits that have been blocked by Exploit Guard. |
exploit-detected | Includes exploits that have only been detected by Exploit Guard. This does not include exploits that have also been blocked. |
indicator-executed | Includes only indicators that have executed. |
indicator-presence | Includes indicators that are present in the environment, including those that have executed. |
malware-object | Includes malware objects that have been detected by Signature and Heuristic Detection or MalwareGuard. |
riskware-infectionmatch | Includes alerts triggered when network traffic or objects match patterns, URLs, or IP addresses identified in a riskware-specific intelligence feed. These alerts represent non-malicious riskware events that pose a potential risk to the environment. |
You can send a test-fire notification from the Central Management System appliance or from managed appliances. There are the following differences:
A test-fire notification sent from a managed appliance contains more information than one sent from the Central Management System appliance.
Notifications sent from the Central Management System appliance do not appear in the Central Management System database or Web UI.
Notifications sent from a managed appliance do appear in the appliance database and Web UI; if they are aggregated up to the Central Management System appliance, they also appear in the Central Management System database and Web UI.
After notifications are aggregated up to the Central Management System appliance, another notification is sent from the Central Management System appliance.
Note
This section describes how to configure event (alert) notifications. See Configuring system email settings for information about system email notifications.