cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2542
Views
0
Helpful
1
Replies

IronPort Alert when a Message is dropped AMP

anotthak8
Level 1
Level 1

I am wondering if there is a way that an email alert can be generated whenever a message is dropped by AMP.

Any insight will be helpful. Thank you in advance!

1 Accepted Solution

Accepted Solutions

Mathew Huynh
Cisco Employee
Cisco Employee

Hello Anotthak,


The only option I can think of is, set Malicious AMP to 'deliver' but add a header.

Then add a content filter to look for this header, and send a notification to your administrator or so and drop the email after.


However I had noted an issue when this is used, if the email gets sent to the AMP quarantine and released for the AMP rescan, if it's deemed malicious, it will deliver the email as is - this is because a second rescan would not put the email through the content filters again.


Regards,

Matthew

View solution in original post

1 Reply 1

Mathew Huynh
Cisco Employee
Cisco Employee

Hello Anotthak,


The only option I can think of is, set Malicious AMP to 'deliver' but add a header.

Then add a content filter to look for this header, and send a notification to your administrator or so and drop the email after.


However I had noted an issue when this is used, if the email gets sent to the AMP quarantine and released for the AMP rescan, if it's deemed malicious, it will deliver the email as is - this is because a second rescan would not put the email through the content filters again.


Regards,

Matthew