McAfee M-1250 IPS Configuration Guide - Page 151

Setting up alert notifications, Viewing alert notification details

Page 151 highlights

McAfee® Network Security Platform 5.1 Managing IPS settings • Cached Reconnaissance policies: The number of reconnaissance policies in Manager cache. • Names of Cached Reconnaissance policies: The names of reconnaissance policies in Manager cache. To clear the Manager Cache, do the following: 1 Select IPS Settings > Maintenance > Manager Pruning. 2 Click Clear Caches. Setting up alert notifications Your Manager can send alert information to third-party machines such as SNMP servers and Syslog servers. You can also configure Manager to notify you-via email, pager, or script-of detected attacks based on the attack or attack severity. You can perform the following tasks with respect to alert notifications: • Viewing alert notification details (on page 143): View the configured parameters of all Alert Notification actions. • Forwarding alerts to an SNMP server (on page 144): Forward Network Security Platform alert information to a defined SNMP server. • Forwarding alerts to a Syslog server (on page 146): Forward Network Security Platform alerts to a defined Syslog server. • Specifying email or pager parameters for alert notification (on page 150): Configure how users are contacted when attacks are detected that require immediate attention. • Specifying script parameters for alert notification (on page 152): Configure a script to be executed when attacks are detected that require immediate attention. Figure 154: Alert Notification Tab Viewing alert notification details The Alert Notification > Summary action displays a summary of configured alert notification settings. The summary reflects configurations made within Alert Notification group actions. 143

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259

McAfee® Network Security Platform 5.1
Managing IPS settings
143
Cached Reconnaissance policies:
The number of reconnaissance policies in Manager
cache.
Names of Cached Reconnaissance policies
: The names of reconnaissance policies in
Manager cache.
To clear the Manager Cache, do the following:
1
Select
IPS Settings > Maintenance > Manager Pruning
.
2
Click
Clear Caches
.
Setting up alert notifications
Your Manager can send alert information to third-party machines such as SNMP servers
and Syslog servers. You can also configure Manager to notify you—via email, pager, or
script—of detected attacks based on the attack or attack severity. You can perform the
following tasks with respect to alert notifications:
Viewing alert notification details (on page
143
): View the configured parameters of all
Alert Notification
actions.
Forwarding alerts to an SNMP server (on page
144
): Forward Network Security
Platform alert information to a defined SNMP server.
Forwarding alerts to a Syslog server (on page
146
): Forward Network Security
Platform alerts to a defined Syslog server.
Specifying email or pager parameters for alert notification (on page
150
): Configure
how users are contacted when attacks are detected that require immediate attention.
Specifying script parameters for alert notification (on page
152
): Configure a script to
be executed when attacks are detected that require immediate attention.
Figure 154: Alert Notification Tab
Viewing alert notification details
The
Alert Notification > Summary
action displays a summary of configured alert notification
settings. The summary reflects configurations made within
Alert Notification
group actions.