11-19-2019 09:04 PM
Hi,
I am working on integrating Mearki alerts (using webhook) with ITSM. To test the functionality I like to test each alerts and see how it reflect in ITSM. Is there any scripts/tool I can use to trigger the alerts specially udldError, malwareDetected, malwareBlocked, portCableError and rougueDHCPServer. I am able to trigger them manually it's really time consuming and I can't do it remotely.
Thanks
Fakrul.
11-19-2019 10:59 PM
I suppose you already know that you can trigger AMP using the EICAR samples (eicar.org).
For rogue DHCP you could just run an open source DHCP server. Tftpd comes to mind.
But you can't do that remotely indeed. Unless you can access a client remotely. And I wouldn't do the DHCP test on a production network.
11-20-2019 01:40 AM
Yes i was able to use EICAR to check malwereBlocked alert. Regarding DHCP I am alwaya getting newDHCPDetected not the rogueDHCP one. Not sure for which scenario rogueDHCP alerts trigger.
11-20-2019 01:45 AM
I haven't tested with it, but is the DHCP server you added handing out addresses in the same range as the MX is?
11-20-2019 10:33 AM
>Is there any scripts/tool I can use to trigger the alerts
No.
11-20-2019 12:28 PM
@fakrulalam I would imagine a rogue DHCP alert would come when a subnet has a second DHCP server added onto it.
11-20-2019 03:04 PM
I have tried putting a new DHCP server (advertising the same prefixes) but still getting NewDHCPservcerdetected alert.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide