Deep Discovery Inspector can send notifications when detecting suspicious hosts. A host is considered suspicious
when the number of detections associated with it reaches the configured threshold.
Suspicious Hosts Detections notifications contain information that can help determine
the cause of the increased detections.
Procedure
- Go to .
- Select Notify administrator if number of detections per IP address.
- Specify the detection threshold.

Tip
Trend Micro recommends using the default settings. - (Optional) Configure the notification recipients.For details, see Configuring Email Notification Settings.
- (Optional) Modify the default subject and message body.

Note
-
The message body cannot exceed 4,096 characters.
-
The message subject cannot exceed 256 characters.
You can use any of the following message tokens when customizing the notification.Message TokenDescription__LOOP_END__End of message token loop__LOOP_HOST_IP__Host IP address__LOOP_INCIDENT_NUMBER__Incident count__LOOP_INCIDENT_THRESHOLD__Incident threshold__LOOP_START__Start of message token loop__TIMESTAMP__Notification date and time
Note
The following tokens repeat as needed inside message token loops:-
__LOOP_HOST_IP__
-
__LOOP_INCIDENT_NUMBER__
-
__LOOP_INCIDENT_THRESHOLD__
-
- Click Save.
