Configuring alerts
From the Security page, you can prioritize security events for an endpoint based on their type and configure one or more targeted alert actions to take every time the event occurs on the endpoint.
Table 1 describes the alert
categories that are available for AIX, Linux, and IBM® i.
The Correlation events category represents a group of events that occur within an interval that you might want to be aware of and that might require additional investigation. See Swagger PUT /correlatedEvents example to configure correlation events.
| Category | AIX | Linux | IBM i |
|---|---|---|---|
| Agent connectivity |
|
|
|
| Allow listing |
|
|
|
| Blocklist |
|
|
|
| Compliance |
|
|
|
| Configuration |
|
|
|
| Correlation Events | SYSTEM BREACH | SYSTEM BREACH | SYSTEM BREACH |
| Status changed |
|
|
|
| File integrity monitoring |
|
|
|
| Host intrusion |
|
|
|
| IBM i Data Capture | NA | NA |
|
| Malware |
|
|
|
| Quantum Analysis Scan |
|
|
|
| Scheduled command failed | NA | NA | NA |
| Patch management |
|
|
|
On the Alert Configuration page, events are categorized as shown in Table 2.
| Event Category | Event Name | Urgency | Responses | Parameters |
|---|---|---|---|---|
| Agent connectivity | One of:
|
One of:
|
None, or one more of:
|
NA |
| Allow listing |
|
One of:
|
None, or one more of:
|
NA |
| Blocklist |
|
One of:
|
None, or one more of:
|
NA |
| Compliance |
|
One of:
|
None, or one more of:
|
NA |
| Configuration |
|
One of:
|
None, or one more of:
|
NA |
| Correlation Events | SYSTEM BREACH | One of:
|
None, or one more of:
|
NA |
| Status changed |
|
One of:
|
None, or one more of:
|
NA |
| File Integrity Monitoring |
|
One of:
|
None, or one more of:
|
NA |
| Host Intrusion |
|
One of:
|
None, or one more of:
|
Password Failures
|
| IBM i Data Capture |
|
One of:
|
None, or one more of:
|
NA |
| Malware |
|
One of:
|
None, or one more of:
|
NA |
| Quantum Analysis Scan |
|
One of:
|
None, or one more of:
|
NA |
| Scheduled command failed | NA | NA | None, or one more of:
|
|
| Patch management 1 |
|
N
|
None, or one more of:
|
Notes:
- 1 The previous Patch
Management event represented several types of events
collectively identified by
UP_TO_DATE_UPDATE. This collective event is deprecated in favor of more delineated events and may be removed in a future release.