02-03-2011 07:44 AM
Is there a way to setup reports to send alerts/reports as soon as something triggers an alert rather than send out every minute/hour/day? So say as soon as MARS sees a P2P session, it will send an alert off to me.
Thanks in Advance.
Solved! Go to Solution.
02-08-2011 02:30 AM
If you locate the report "Activity: P2P Filesharing/Chat - All Events" then you will see the event tyope as
Info/UncommonTraffic/P2PFileShare, Info/UncommonTraffic/P2PFileShare/FileTransfer,
Info/UncommonTraffic/Chat, Info/UncommonTraffic/Chat/FileTransfer, Info/UncommonTraffic/Chat/Proxy
You can then make a query, "all event raw messages". Under event, one at a time locate the 5 event types listed above and select all of the events listed for each (eg: Yahoo messag=nger missing URL, Yahoo instant messanger file transfer...etc). Cick apply and then "save as rule". You can then configure the rule as required. eg: limit to specific source/.dest subnets. Specifiy the action as email. If you want to be alerted for each and every occurrence, then you should set the time to something short like 1 minute. You can review the list of events and remove any that might not be applicable.
Matthew
02-08-2011 02:30 AM
If you locate the report "Activity: P2P Filesharing/Chat - All Events" then you will see the event tyope as
Info/UncommonTraffic/P2PFileShare, Info/UncommonTraffic/P2PFileShare/FileTransfer,
Info/UncommonTraffic/Chat, Info/UncommonTraffic/Chat/FileTransfer, Info/UncommonTraffic/Chat/Proxy
You can then make a query, "all event raw messages". Under event, one at a time locate the 5 event types listed above and select all of the events listed for each (eg: Yahoo messag=nger missing URL, Yahoo instant messanger file transfer...etc). Cick apply and then "save as rule". You can then configure the rule as required. eg: limit to specific source/.dest subnets. Specifiy the action as email. If you want to be alerted for each and every occurrence, then you should set the time to something short like 1 minute. You can review the list of events and remove any that might not be applicable.
Matthew
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide