Notifications_Critical_Risks

Real-time Notification for Critical Security Risks

Threat Discovery Appliance triggers real-time notifications as soon as it detects critical security risks in the network to allow you to take immediate action. You can configure the product to send these notifications immediately or at specified intervals.

By default, the product will send notifications for critical security risks detected on all endpoints. Use the exclusion list for endpoints that you do not want to be notified about.

  1. Select the option to enable real-time notifications.

  2. Under Potential Security Risks, select the option to send a notification when a high-severity security risk is detected.

  3. Under Known Security Risks, select the option to send a notification when virus/malware or spyware/grayware is detected.

  4. Specify the email-sending interval in number of minutes, hours, or days.

  5. For each endpoint, Threat Discovery Appliance aggregates notifications triggered within the time interval and sends them as one email message when the time interval elapses. For example, if critical security risks were detected on 12 endpoints, Threat Discovery Appliance sends 12 email messages. Each message contains a list of critical security risks detected in the endpoint within the time interval.

  6. Click Save.

  1. Click the Exclusion List tab.

  2. Type a descriptive name for the exclusion list.

  3. Type the IP address/range of endpoints to be excluded from real-time notifications.

  4. Click Add.

  5. To remove an exclusion list, mark the check box before the exclusion list and then click Delete.

  6. Click Save.

See also: