To receive alerts from the target: |
|
This function lets you:
This is what the page looks like:
Area | Description | ||||||||
---|---|---|---|---|---|---|---|---|---|
1 |
RCS menu.
|
||||||||
2 |
Alert rule toolbar. Descriptions are provided below:
|
||||||||
3 |
Alert log toolbar. Descriptions are provided below:
|
||||||||
4 |
RCS menu. |
For interface element descriptions
For a description of the data in this window
For more information on alerts
A rule must be set in order for you to be alerted:
Step | Action |
---|---|
1 |
Click New Alert: data entry fields appear. |
2 |
|
3 |
Click Save: the new alert rule appears in the main work area. An alert is sent as soon as the system receives evidence that matches the rule. |
To edit an alert rule
Step | Action |
---|---|
1 |
Select the alert rule to be edited Click Edit: the data to be edited appears. |
2 |
|
3 |
Click Save: the new alert rule appears in the main work area. An alert is sent as soon as the system receives evidence that matches the rule. |
To automatically tag certain evidence without logging or sending alerts:
Step | Action |
---|---|
1 |
Click New Alert: data entry fields appear. |
2 |
|
3 |
Click Save: the new alert rule appears in the main work area. As soon as the system receives evidence matching this rule, the evidence is tagged. |
To view evidence matching an alert:
Step | Action |
---|---|
1 |
Select the alert rule with at least one log (Logs column): all logged alerts appear in the list. |
2 |
In the logged alert list, double-click the Evidence column: the list of evidence that triggered the alert appears. |