Creating an email notification for a failed backup
To receive a notification by email about a backup failure on the IBM
QRadar Console or a QRadar Event Processor, create a
rule that is based on the system notification message.
Before you begin
You must configure an email server to distribute system notifications in QRadar. For more information, see
Configuring your local firewall.
About this task
If a backup fails, you see one of the following backup failure system notifications:
Backup: requires more disk space
Backup: last Backup exceeded execution threshold
Backup: unable to execute request
Procedure
Click the Offenses tab.
In the Offenses pane, click Rules.
Click Actions > New Event Rule.
In the Rule Wizard, check the Skip this page when running this
rules wizard box and click Next.
In the filter box, type the following search query:
when the event QID is one of the following QIDs
Learn more about tests:Figure 1. Rule Wizard event test
Click the green add (+) icon.
In the Rule pane, click the QIDs link.
In the QID/Name field, type Backup:
Select the following QIDs and click Add +:
Backup requires more disk space
Backup: last backup exceeded execution threshold
Backup unable to execute request
Learn more about QIDs:Figure 2. Rule Wizard QIDs
Click Submit.
In the Rule pane, type the following name for your rule test and click
Next:
Backup Failure
In the Rule Response section, check the Email box
and type the email addresses you want to notify.