Topic
  • 3 replies
  • Latest Post - ‏2016-08-26T13:54:44Z by Mike Hardesty
ManasSarma
ManasSarma
2 Posts

Pinned topic Why emails are not triggering for all rule matches?

‏2016-08-26T10:34:41Z | alert email rule

I have configured a few rules in Qradar. I have tested the rules and they are creating offenses as expected. I have added email alert as a response to all the rules. There is no difference in the response configuration of the rules. But, only a couple of rules are sending email alerts and rest all are not. One rule that is generating email is event based and other one is flow based. So, it is nothing to do with the type either. 

 

It would be really helpful if anyone can point out what may be wrong.

 

Thanks,

Manas

  • Mike Hardesty
    Mike Hardesty
    2 Posts

    Re: Why emails are not triggering for all rule matches?

    ‏2016-08-26T13:00:04Z  

    Do you have a response limiter set on the rules? 

  • ManasSarma
    ManasSarma
    2 Posts

    Re: Why emails are not triggering for all rule matches?

    ‏2016-08-26T13:06:11Z  

    Do you have a response limiter set on the rules? 

    Yes, I do have. But response limiter settings are also same on all of them. No difference between the triggered and non-triggered ones. I have also closed all active offenses to see if anything changes, but no luck there as well.

  • Mike Hardesty
    Mike Hardesty
    2 Posts

    Re: Why emails are not triggering for all rule matches?

    ‏2016-08-26T13:54:44Z  

    You could try to temporarily disable the limiter on the rule you are testing then cause the rule to fire. My other thought would be perhaps in the past something was added to a falsepositiveBB to prevent that rule from being fired?