67
ePolicy Orchestrator
®
3.6 Walkthrough Guide
ePolicy Orchestrator Notifications
Viewing the history of Notifications
6
Creating rules
Creating a rule is a four-step process:
1
Describe the rule — Naming the rule and defining the level of the
Directory
to which
it applies.
2
Set filters for the rule — Specifying the products, event categories, and any threat
names that apply to the rule.
3
Set thresholds of the rule — Defining the aggregation and throttling of the rule.
4
Configure the notifications for the rule — Defining the messages you want sent,
their delivery type, and any executables you want to run when the rules conditions
are met.
For complete instructions, see the
ePolicy Orchestrator 3.6 Product Guide
.
Viewing the history of Notifications
This feature allows you to view the history of notifications sent. You can view a
collective summary of all notifications sent, by product or category, or a list of all the
specific notifications sent.
Virus detected and
not removed
Virus Detected and Not
Removed
events from
any product.
Sends a notification message:
When the number of events exceeds
1000 within an hour.
At most, once every two hours.
With the source system IP address,
actual threat names, and actual product
information, if available.
Virus detected
heuristics and not
removed
Virus Detected
(Heuristics) and Not
Removed
events from
any product.
Sends a notification message:
When the number of events exceeds
1000 within an hour.
At most, once every two hours.
With the source system IP address,
actual threat names, and actual product
information, if available.
Repository Update or
Replication Failed
Repository update or
replication failed
events.
Sends a notification message when any
events are received.
Non-compliant
computer detected
Non-compliant
Computer Detected
events.
Sends a notification message:
When any events are received.
Once per each rule of the Compliance
Check server task. (This task sends one
event per each of the four rules
associated with the Compliance Check
server task.)
Table 6-1 Default notification rules
Rule name
Associated events
Configurations
Содержание ePolicy Orchestrator
Страница 2: ......