cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1108
Views
0
Helpful
6
Replies

CSA / Securityworks not sending alert emails.

cdillon12
Level 1
Level 1

CSA installed and in test mode collecting events. Working through rules, and policies. (If anyone has a down and dirty way to do that, I would greatly appreciate it, CSA is a huge can of worms)

So, under Security agent, event, alert. I set it up to send an email for ALL ALERTS. Simply to see if it works. I enter a valid internal company email, as the Recipient, and a valid company internel email as the sender. For the address of mail server I have Servername.network.net. Put in a 'subject' line.

Then after a few minutes I get an event, and this shows up.

410 6/20/2007 3:11:13 PM - Warning The notification process failed to send 1 alert(s) using mail alert 'Network and Security Team Notify'.

123 similar events (same Type/Rule ID/Application)Find Similar

Tried changing the sender / the recipient, the server to the ip address. Still the same message. What am I doing wrong. Doesnt look that difficult.

6 Replies 6

Not applicable

I think you have to create an event set from the event set page to include only alerts. The option for alert only is not available by default when configuring events to be sent to your email. Following link may help you to learn how to create an event set that you can use to configure an alert:

http://cisco.com/en/US/docs/security/csa/csa45/user_guide/Chap8.html

tsteger1
Level 8
Level 8

Sounds like the mail server either isn't allowing it to work or is not configured correctly.

Do you have other alerts using the same server?

The only time I see messages like that is if I misconfigure the smtp server or type in the address wrong in the alert.

Tom

Just getting CSA rolling actually. This is a test "alert". I have several "event sets" and I have tried to send alerts using each evnet set.

In the configuration, I am using my email address as the person to get the email. For the sender, I have used my own, valid email, and I have tried a 'bogus' email (csa_alert@company.com)

I have used the dns name in various configurations "servername.company.net" or just "servername" Also the direct IP of the server.

There has to be some kind of setting or 'check box' that I am missing somewhere.

The alerting part and all is working correctly or you wouldn't get the warning about not sending.

Are you using this mail server to send alerts in other applications?

Yes. This is my primary mail server for this location. The same one I get my mail from. I have other applications that use this functionality.. Example - my AS400, Veritas Backup Exec.. I get notices from those applications, regarding alerts, and issues.

The CSA server is on the same lan / subnet / and can ping / communicate with the Exchange server.

For example.. backup exec.. the information is configured the same.. "Server.company.net" with a bogus email. Veritas@company.com That is not a valid Active directory account. Just to know where it comes from.

Just for kicks, set the alert to log to a text file and disable security on the MC for a bit and see what happens.

SMTP should work if you have the CSA MC Systems group at the defaults.

Turning off security should eliminate any rules as the culprit and the text log will tell you if your alert is functioning.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: