Critical Alerts Parent topic

The following table explains the critical alerts triggered by events requiring immediate attention.
Critical alerts are enabled by default.

Critical Alerts

Name
Default Criteria
Default Alert Frequency
Security: Multiple Advanced Threats Detected in Specified Network Groups
10 or more advanced threats detected on hosts
Once every 5 minutes
Security: Multiple Ransomware Detected in Specified Network Groups
10 or more ransomware detections on hosts
Once every 5 minutes
Security: Multiple C&C Callbacks Detected in Specified Network Groups
10 or more C&C callbacks detected on hosts
Once every 5 minutes
Security: Multiple Coin Miners Detected in Specified Network Groups
10 or more coin miner detections on hosts
Once every 5 minutes
System: Service Stopped/Abnormal
Service % has stopped and cannot be restarted
Immediate
System: License Expiration
License is about to expire or has expired
Immediate
System: Network Is Down
Device %s's network is down
Immediate