Procedure
- Go to .The Administrator Notifications screen appears.
- In the Criteria tab:
- Go to the Virus/Malware and Spyware/Grayware sections.
- Specify whether to send notifications when Trend Micro Apex One detects virus/malware and spyware/grayware, or only when the action on these security risks is unsuccessful.
- In the Email tab:
- Go to the Virus/Malware Detections and Spyware/Grayware Detections sections.
- Select Enable notification via email.
- Select Send notifications to users with agent tree domain
permissions.You can use Role-based Administration to grant agent tree domain permissions to users. If a detection occurs on any Security Agent belonging to a specific domain, the email will be sent to the email addresses of the users with domain permissions. See the following table for examples:
Agent Tree Domains and Permissions
Agent Tree DomainRoles with Domain PermissionsUser Account with the RoleEmail Address for the User AccountDomain AAdministrator (built-in)rootmary@xyz.comRole_01admin_johnjohn@xyz.comadmin_chrischris@xyz.comDomain BAdministrator (built-in)rootmary@xyz.comRole_02admin_janejane@xyz.comIf any Security Agent belonging to Domain A detects a virus, the email will be sent to mary@xyz.com, john@xyz.com, and chris@xyz.com.If any Security Agent belonging to Domain B detects spyware, the email will be sent to mary@xyz.com and jane@xyz.com.Note
If you enable this option, all users with domain permissions must have a corresponding email address. The email notification will not be sent to users without an email address. Users and email addresses are configured from. - Select Send notifications to the following email address(es) and then type the email addresses.
- Specify the Subject used in the email notification.
- Specify the Message contents.Trend Micro Apex One supports use of tokens in the Subject and Message fields.
Token Variables for Security Risk Notifications
Variable TokenDescriptionVirus/Malware detections%vSecurity threat name%sEndpoint with the detection%iIP address of the endpoint%cMAC address of the endpoint%mDomain of the endpoint%pLocation of virus/malware%yDate and time of detection%eVirus Scan Engine version%rVirus Pattern version%aAction performed on the security risk%nName of the user logged on to the endpoint%gGUID of the Security Agent%bScan typeSpyware/Grayware detections%sEndpoint with the detection%iIP address of the endpoint%mDomain of the endpoint%yDate and time of detection%nName of the user logged on to the endpoint%TSpyware/Grayware and scan result%dDetailed information regarding spyware/grayware detection%gGUID of the Security Agent%bScan type
- In the SNMP Trap tab:
- Go to the Virus/Malware Detections and Spyware/Grayware Detections sections.
- Select Enable notification via SNMP trap.
- Accept or modify the default message. You can use token variables in the following
table to
represent data in the Message field.
Token Variables for Security Risk Notifications
VariableDescriptionVirus/Malware detections%vSecurity threat name%sEndpoint with the detection%iIP address of the endpoint%cMAC address of the endpoint%mDomain of the endpoint%pLocation of virus/malware%yDate and time of detection%eVirus Scan Engine version%rVirus Pattern version%aAction performed on the security risk%nName of the user logged on to the endpoint%gGUID of the Security Agent%bScan typeSpyware/Grayware detections%sEndpoint with the detection%iIP address of the endpoint%mDomain of the endpoint%yDate and time of detection%nName of the user logged on to the endpoint%TSpyware/Grayware and scan result%vSecurity threat name%aAction performed on the security risk%dDetailed information regarding spyware/grayware detection%gGUID of the Security Agent
- In the NT Event Log tab:
- Go to the Virus/Malware Detections and Spyware/Grayware Detections sections.
- Select Enable notification via NT Event Log.
- Accept or modify the default message. You can use token variables in the following
table to
represent data in the Message field.
Token Variables for Security Risk Notifications
VariableDescriptionVirus/Malware detections%vSecurity threat name%sEndpoint with the detection%iIP address of the endpoint%cMAC address of the endpoint%mDomain of the endpoint%pLocation of virus/malware%yDate and time of detection%eVirus Scan Engine version%rVirus Pattern version%aAction performed on the security risk%nName of the user logged on to the endpoint%gGUID of the Security Agent%bScan typeSpyware/Grayware detections%sEndpoint with the detection%iIP address of the endpoint%mDomain of the endpoint%yDate and time of detection%nName of the user logged on to the endpoint%TSpyware/Grayware and scan result%vSecurity threat name%aAction performed on the security risk%dDetailed information regarding spyware/grayware detection%gGUID of the Security Agent
- Click Save.