Email notification content is too large; pauses/crashes Outlook 365

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Email notification content is too large; pauses/crashes Outlook 365

L0 Member

We have deployed a proof of concept of XDR with 30+ agents. As the system is still gathering information, we have been receiving  e-mail notifications from the activities its collecting. Some e-mails vary from 100KB to 7MB in size per e-mail. It's at a point that there's a significant delay (Outlook 365) browsing these messages to an annoyance. The mobile Outlook crashes attempting to view these e-mails and the desktop Outlook has significant pauses when the message is highlighted.

1. Is anyone else experiencing issues with large XDR e-mail notifications?

2. Is there a way to display the e-mail notification with a brief summary instead of the entire json content?


L2 Linker

The size of the email depends on how many alerts get grouped together, and the volume of alerts notification, which is directly related to the notification filter you set. 

For example, you could experience a huge volume due to low severity and NGFW alerts, depending on your environment. 
You could optimize your configuration by forwarding only the critical alerts to your email. You may use a filter like alert source =! NGFW, severity = High, excluded = No.
Note: You do not lose visibility of the remaining alerts as you can login to your tenants and respond to the low severity ones.
If the size problem persists, you could modify the "Grouping Timeframe" parameter.
  • 1 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!