Views:

The following table explains the important alerts triggered by events that require observation. Deep Discovery Email Inspector considers traffic surges, suspicious message detections, hardware capacity changes, certain sandbox queue activity, and component update issues as important events.

Table 1. Important Alerts

Name

Criteria

(Default)

Checking Interval

(Default)

Suspicious Messages Identified

1 or more messages detected with threats

Once every 5 minutes

Watchlisted Recipients at Risk

1 or more messages detected with threats sent to watchlist recipients

Once every 5 minutes

Quarantined Messages with Detected Threats

At least 10 messages quarantined

Once every 30 minutes

Long Message Delivery Queue

At least 500 messages in delivery queue

Once every 5 minutes

High CPU Usage

CPU usage is at least 90%

Once every 5 minutes

Long Virtual Analyzer Submission Queue

At least 20 messages in queue for Virtual Analyzer submission with a wait time of 5 minutes

Immediate

Long Virtual Analyzer Processing Time

Average Virtual Analyzer processing time is greater than 15 minutes

Once every hour

Low Free Disk Space

Disk space is 5GB or less

Once every 30 minutes

Component Update/Rollback Unsuccessful

An update/rollback was not successful

Immediate

Email Messages Timed Out Without Analysis Results

At least 1 email message timed out without analysis results

Once every 5 minutes

Email Message Encryption/Decryption Unsuccessful

At least 1 message with unsuccessful encryption or decryption

Once every 5 minutes

Low Free Threat Quarantine Disk Space

Free quarantine disk space left to store messages with detected threats is 10% or less

Once every 30 minutes

High Memory Usage

Memory usage is at least 90%

Once every 5 minutes

Long Message Deferred Queue

At least 100 messages in deferred queue

Once every 5 minutes

Low Free Spam Quarantine Disk Space

Free quarantine disk space left to store spam messages is 10% or less

Once every 30 minutes

Account Locked

One or more accounts have been locked

Immediate

Unsuccessful DKIM Signing

At least 5 messages with unsuccessful DKIM signing

Once every 5 minutes

Connection Issue

Unable to establish connection to a required resource

Once every 30 minutes