Sending email notifications

Share the offense summary information with another person by sending an email.

The body of the email message includes the following information, if available:
  • Source IP address
  • Source user name, host name, or asset name
  • Total number of sources
  • Top five sources by magnitude
  • Source networks
  • Destination IP address
  • Destination user name, host name, or asset name
  • Total number of destinations
  • Top five destinations by magnitude
  • Destination networks
  • Total number of events
  • Rules that caused the offense or event rule to fire
  • Full description of the offense or event rule
  • Offense ID
  • Top five categories
  • Start time of the offense or the time the event was generated
  • Top five annotations
  • Link to the offense user interface
  • Contributing CRE rules

Procedure

  1. Click the Offenses tab.
  2. Select the offense for which you want to send an email notification.
  3. From the Actions list box, select Email.
  4. Configure the following parameters:
    Option Description
    Parameter Description
    To Type the email address of the user you want to notify when a change occurs to the selected offense. Separate multiple email addresses with a comma.
    From Type the originating email address. The default is root@localhost.com.
    Email Subject Type the subject for the email. The default is Offense ID.
    Email Message Type the standard message that you want to accompany the notification email.
  5. Click Send.