Symantec 10551441 Administration Guide - Page 63

Configuring alert actions, Alert configuration tasks

Page 63 highlights

Setting up the Alert Management System 63 Configuring alert actions Configuring alert actions AMS2 lets you configure many different methods of notification-such as pager, SNMP, and email-for detected threats and configuration changes. Alert configuration tasks AMS2 alert configuration requires the following related tasks: ■ Select an alert in the Alert Actions dialog box. ■ Select the alert action that you want to configure for that alert. The alert action is the response AMS2 sends you when an alert parameter is detected. ■ Configure the alert action that you selected. For example, you could configure the Send Page alert action to notify you if a threat was detected on a protected server. The pager message could also include information such as threat name and type, and actions taken on the infected file. There are no default alert actions for any of the alerts. Until you configure AMS2, no alerts are generated, though threat events are logged in the AMS2 log file. You can set up more than one action for each alert. Once you have configured alert actions for an alert, a plus (+) or minus (-) sign appears next to each configured alert, depending on whether the entry is collapsed or expanded. Each AMS2 alert action has its own configuration wizard. Once you have configured an alert action, the action appears in the Alert Actions dialog box under the alert for which you configured the action. All alert actions execute on the computer that you select when you configure the action. Actions will not execute if you configure them on a computer that doesn't support that particular action. For example, any computer that you configure the Send Page action on must have a modem.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

63
Setting up the Alert Management System
Configuring alert actions
Configuring alert actions
AMS
2
lets you configure many different methods of notification—such as pager,
SNMP, and email—for detected threats and configuration changes.
Alert configuration tasks
AMS
2
alert configuration requires the following related tasks:
Select an alert in the Alert Actions dialog box.
Select the alert action that you want to configure for that alert. The alert
action is the response AMS
2
sends you when an alert parameter is detected.
Configure the alert action that you selected.
For example, you could configure the Send Page alert action to notify you if a
threat was detected on a protected server. The pager message could also include
information such as threat name and type, and actions taken on the infected file.
There are no default alert actions for any of the alerts. Until you configure
AMS
2
, no alerts are generated, though threat events are logged in the AMS
2
log
file.
You can set up more than one action for each alert. Once you have configured
alert actions for an alert, a plus (+) or minus (-) sign appears next to each
configured alert, depending on whether the entry is collapsed or expanded.
Each AMS
2
alert action has its own configuration wizard. Once you have
configured an alert action, the action appears in the Alert Actions dialog box
under the alert for which you configured the action.
All alert actions execute on the computer that you select when you configure the
action. Actions will not execute if you configure them on a computer that
doesn’t support that particular action. For example, any computer that you
configure the Send Page action on must have a modem.