How can I create an e-mail alert that includes actual information about the event that triggered it?
Like for example, knowing a TCP Syn Host Sweep occured and met the threshold I set for my alert is faaar less useful than knowing 10.10.10.10 triggered it and not only met the threshold but triggered the alert 10,000 times.
I am running VMS 2.3 managing 5.x IPS sensors.
If VMS cannot do this then its officially a piece of shit.
Also, if VMS cannot do this, can MARS or CSM?