Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • Here a set of Events is to be set to get notified for. Those events are categorized as Agent, Company, Asset, Ports, Remediation, Vulnerability, Azure error, and AD Audit. Every category will have certain events which can be set.

  • Enter the Event Name and select the category and an Event/s as required.

  • Every Category has a set of events/alerts under them which can be selected as per the requirement.

...

  • The Agent & Company category has the below-listed alerts and selection of all or any is allowed.

...

  • The Remediation category has the Remediation Group, selection of Remediation by Company OR Remediation by Assets OR Remediation by Product OR Remediation by Product(grouped by a fix), Remediation by Asset and Product is allowed, and Enable Remediation for Critical and High Severity(Select any one of them).

  • For the Remediation Filters, Enable Tickets for Critical High severity Remediations, Enable Tickets for Remediations with EPSS greater than 0.95, Enable Tickets for Remediations with EPSS greater than 0.90, Enable Tickets for Remediations with EPSS greater than 0.85, Enable Tickets for Remediations with EPSS greater than 0.50

...

  • For the Vulnerability & Azure error category, the below-listed alert, and selection is allowed.

...

  • For the AD Audit category below-listed alerts are available and selection of all or any is allowed. (Make sure to select the needed as it will create tickets based on the events)

...

  • For the Azure AD Audit & Unquoted service path category, the below-listed alert, and selection is allowed.

...

  • For the Reports, the below-listed alerts and selections are allowed.

...

  • Once the above details are selected, click on Save.

...

  • There is an option to Edit, Delete and set as default, for the Alert Rules using the Action column. The listed Alert Rule can be edited and deleted if needed.

...