<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Email alerts for Security Intelligence events in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/email-alerts-for-security-intelligence-events/m-p/3599287#M979735</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correlation policy should be most recommended as we can expect many alert on SI if you connect to internet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 May 2018 04:05:52 GMT</pubDate>
    <dc:creator>smusijar</dc:creator>
    <dc:date>2018-05-18T04:05:52Z</dc:date>
    <item>
      <title>Email alerts for Security Intelligence events</title>
      <link>https://community.cisco.com/t5/network-security/email-alerts-for-security-intelligence-events/m-p/3599284#M979700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any way to setup email alerts for Security Intelligence events?&amp;nbsp; I haven't seen anything other than syslog and SNMP traps.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2018 18:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-alerts-for-security-intelligence-events/m-p/3599284#M979700</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2018-03-14T18:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Email alerts for Security Intelligence events</title>
      <link>https://community.cisco.com/t5/network-security/email-alerts-for-security-intelligence-events/m-p/3599285#M979712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all, you must to setup an email SMTP server in the "System Policy" or "Sysem Settings" in your Firesight Management Center (FMC) or Defense Center (DC). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that, here you are the steps to send "Security Intelligence" events via email:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="SecurityIntelligence1.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117029_SecurityIntelligence1.png" style="height: 111px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="SecurityIntelligence2.png" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/117030_SecurityIntelligence2.png" style="height: 175px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Juan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2018 12:11:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-alerts-for-security-intelligence-events/m-p/3599285#M979712</guid>
      <dc:creator>jsenovilla</dc:creator>
      <dc:date>2018-05-11T12:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Email alerts for Security Intelligence events</title>
      <link>https://community.cisco.com/t5/network-security/email-alerts-for-security-intelligence-events/m-p/3599286#M979724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in addition to setting up the "mail notification: in the system settings, you'll have to create a correlation policy&amp;amp;rule to match an event. Then you can use an email action to alert you. So there's really three things you need to be aware of. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- "email notification" under system settings&lt;/P&gt;&lt;P&gt;- "email action" under policies, actions&lt;/P&gt;&lt;P&gt;- "correlation policy" under policies, correlation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first step is to setup your mail relay. Once that's verified working, you need to setup your email action. With that done, you move on to a correlation policy. These can be a bit daunting at first, but once you learn the flow, it's all just a big logic engine/policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correlation:&lt;/P&gt;&lt;P&gt;- Add a rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Name it&lt;/P&gt;&lt;P&gt;- build your rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - "If connection event occurs...."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Security Intelligence category is &amp;lt;category&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - save&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- add correlation policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - name it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - add rules&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - select and add rule you just made&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - click on "responses" icon next to delete icon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - choose email action you created earlier&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - save&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Activate policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - click the blue slider&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Play around with the correlation policies and you'll quickly see how useful these can be. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2018 23:26:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-alerts-for-security-intelligence-events/m-p/3599286#M979724</guid>
      <dc:creator>miculp</dc:creator>
      <dc:date>2018-05-17T23:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: Email alerts for Security Intelligence events</title>
      <link>https://community.cisco.com/t5/network-security/email-alerts-for-security-intelligence-events/m-p/3599287#M979735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correlation policy should be most recommended as we can expect many alert on SI if you connect to internet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 May 2018 04:05:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-alerts-for-security-intelligence-events/m-p/3599287#M979735</guid>
      <dc:creator>smusijar</dc:creator>
      <dc:date>2018-05-18T04:05:52Z</dc:date>
    </item>
  </channel>
</rss>

