Email laerts for just zone protection alerts

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Email laerts for just zone protection alerts

L1 Bithead

Hello all,

 

I have applied a zone protection profile to the outside zone on my firewall. I am wondering how I can configure the firewall to receive email notifications just for alerts for this zone protection profile. Like every time an IP address is blocked by the firewall.

 

Thank you

3 REPLIES 3

Cyber Elite
Cyber Elite

@MostafaSafari,

I'm not sure you can actually do something like this easily to be honest. The ZPP creates a number of different subtype events in your threat logs whenever the policy is violated, but they aren't universally only present in ZPP violations and will also show up in DoS/DDoS events as well.

 

 

Cyber Elite
Cyber Elite

Hello,

 

Depends on exactly what you are looking for but here is an example. On your log filtering profile your can add on a threat filter, add the filter for logs you're looking for (in my example Im using "( subtype eq 'packet' ) and ( action eq 'drop' )". Then create and an email profile. When you create the email profile you can send a test from it as well to ensure the profile works. If you use Strata Logging Service (previously Cortex Data Lake) you can do something like the second image.

Claw4609_0-1714761124826.png

Claw4609_2-1714761302961.png

 

 

Thank you @Claw4609. I think I need to do some tests as you suggested.

  • 1063 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!