cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
825
Views
0
Helpful
1
Replies

MARS - Email Alerts as Triggered?

jnlawrence76
Level 1
Level 1

Is there a way to setup reports to send alerts/reports as soon as something triggers an alert rather than send out every minute/hour/day?  So say as soon as MARS sees a P2P session, it will send an alert off to me.

Thanks in Advance.

1 Accepted Solution

Accepted Solutions

mwinnett
Level 3
Level 3

If you locate the report "Activity: P2P Filesharing/Chat - All Events" then you will see the event tyope as

Info/UncommonTraffic/P2PFileShare, Info/UncommonTraffic/P2PFileShare/FileTransfer,
Info/UncommonTraffic/Chat, Info/UncommonTraffic/Chat/FileTransfer, Info/UncommonTraffic/Chat/Proxy

You can then make a query, "all event raw messages". Under event, one at a time locate the 5 event types listed above and select all of the events listed for each (eg: Yahoo messag=nger missing URL, Yahoo instant messanger file transfer...etc). Cick apply and then "save as rule". You can then configure the rule as required. eg: limit to specific source/.dest subnets. Specifiy the action as email. If you want to be alerted for each and every occurrence, then you should set the time to something short like 1 minute. You can review the list of events and remove any that might not be applicable.

Matthew

View solution in original post

1 Reply 1

mwinnett
Level 3
Level 3

If you locate the report "Activity: P2P Filesharing/Chat - All Events" then you will see the event tyope as

Info/UncommonTraffic/P2PFileShare, Info/UncommonTraffic/P2PFileShare/FileTransfer,
Info/UncommonTraffic/Chat, Info/UncommonTraffic/Chat/FileTransfer, Info/UncommonTraffic/Chat/Proxy

You can then make a query, "all event raw messages". Under event, one at a time locate the 5 event types listed above and select all of the events listed for each (eg: Yahoo messag=nger missing URL, Yahoo instant messanger file transfer...etc). Cick apply and then "save as rule". You can then configure the rule as required. eg: limit to specific source/.dest subnets. Specifiy the action as email. If you want to be alerted for each and every occurrence, then you should set the time to something short like 1 minute. You can review the list of events and remove any that might not be applicable.

Matthew

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: