Configure the following event notification to notify administrators when communication between an endpoint and a known C&C callback address has been detected.
The Event Notifications screen appears.
A list of events appears.
The C&C Callback Alert screen appears.
Settings |
Description |
---|---|
C&C list source |
Select one or more C&C list sources. |
The selected contact groups or user accounts appear in the Selected Users and Groups list.
Method |
Description |
---|---|
Email message |
To customize the email notification template, use supported token variables or modify the text in the Subject and Message fields. For more information, see Standard Token Variables and C&C Callback Token Variables. |
Windows event log |
To customize the notification template, use supported token variables or modify the text in the Message field. For more information, see Standard Token Variables and C&C Callback Token Variables. |
Syslog |
Apex Central can direct syslogs to supported third-party products, including Cisco Security Monitoring, Analysis and Response (MARS). |