Alert rule data is described below:
Data | Description | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Logs |
(only in a table) Amount of notifications received matching the rule. |
||||||||||||
Enabled |
Enables or disables the alert rule. |
||||||||||||
Event |
Type of event that triggers the alert:
|
||||||||||||
Path |
operation, target, agent and factory whose evidence and synchronizations are to be monitored. Thus it indicates the rule application field. For example, if an operation is selected, all operation evidence is monitored. If an agent is selected, that agent's evidence is monitored. |
||||||||||||
Evidence |
(only Evidence type events) Type of evidence that generates alerts. Tip: '*' indicates all types of evidence. For a description of all types |
||||||||||||
Keyword |
(only Evidence type events) Keyword that the evidence must contain to trigger the alert. For example, keyword "password" creates an alert when the evidence (audio, document) contains the word "password". |
||||||||||||
Tag |
(only Evidence type events) Automatically tags evidence with different levels of relevance to make it easier to search for the most important evidence in the analysis phase:
|
||||||||||||
Type |
Type of alert to be received when evidence arrives:
|
||||||||||||
Suppression Time |
(only Mail type alerts) Latency time for sending identical alert e-mails. Used to avoid identical e-mails after the first. For example, if the target has not communicated its evidence for a while and e-mail alert was selected, you may be bombarded with e-mails when the first evidence arrives. Set a 30-minute Suppression time to receive one e-mail every 30 minutes. NOTE: this setting only limits e-mail delivery. Evidence is always logged. |
Alert logs are described below:
Data | Description |
---|---|
Time |
alert time-date. |
Path |
Range of action from which the alert was generated. For example, if a target was selected in the rule Path, the name of the target and the name of the operation it belongs to will appear here. |
Evidence |
Amount of evidence that generated the alert. |