To create an alert rule
Click Add Rule.
Set Redundancy Filter.
The Alert Redundancy Filter allows you to define the time in seconds that the same alert is logged. The Alert Redundancy Filter has a default setting of 2 minutes and for Threats default setting is 5 minutes. You can set the Redundancy Filter between 30 seconds to 6 hours.
Select the Alert Type, Sub-Type and enter the information based on the selection to include in the rule.
| Alert Type | Sub-Type | Action |
|---|---|---|
| Network Usage |
Application Bandwidth (default) |
Enter a maximum App Bandwidth (Mbps). |
|
Total Interface Bandwidth |
Enter a maximum Interface Bandwidth (Mbps). |
|
|
Max Connection Count |
Enter a maximum Connection Count in (K Connections). |
|
|
CPU Usage |
Enter a maximum CPU Usage (%) |
|
| Per Interface | Select the Interface(s) and define the Packet Rate (PPS), Bandwidth (MBPS), Connection Rate (CPS) for the selected interface(s). | |
| Threats |
|
|
| Web Activities |
Websites (default) |
Add the websites to be included in the rule.
|
| Web Categories | Select the web categories to be included from Not In Group list and click the caret-right icon to add to the In Group list. | |
| Geo-Locations | Countries (default) | Select the countries to be included from Not In Group list and click the caret-right icon to add to the In Group list. |
| System Events |
Site-to-Site VPN (default) |
|
|
Firewall Reboot |
||
|
WAN Probe Failure |
||
| Cloud Secure Edge | ||
| Attack Logs |
Set the notification Actions.
By the default, all the options are disabled.
| System Alerts | Enable Show Alerts for this Notification to get alerts in Notification Center. |
| Enable Send Email Notifications to get alert notifications through the Email. | |
| History |
Enable Save notifications to save the notifications under the Firewall View | Monitor > Alerts & Notifications > History page. For more information, refer to History of Alerts and Notifications. Enter the number of Days that the saved notifications to be retained. You can set between 1 and 10 days. The default value is 10 days. |