cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
395
Views
0
Helpful
6
Replies

MARS email alert notifications

randytoni
Level 1
Level 1

hi

when a rule fires on MARS, and the incident triggers an email alert, the contents of that email contain the incident #, the name of the rule that fired, and the respective links to the incident details.

Is there any way to customize the email alerts (e.g. add some other incident-specific parameters to the message)?

thanks

-randy

6 Replies 6

a.kiprawih
Level 7
Level 7

Hi,

Based on the v4.2 doc, the alert notifications cannot be customized. Maybe they should have that feature available too.

http://www.cisco.com/en/US/partner/products/ps6241/products_user_guide_chapter09186a00806b614c.html

Rgds,

AK

thanks for the info - yes it would be a nice feature.

-randy

Thanks for the reference.

Is there an improvement???

I haven't received a notification recently, but is the rule that is triggered listed in the e-mail/SMS? I don't recall seeing this on prior alarm messages, which listed an incident number only (Useless until logging onto Mars).

Someone please correct me if I'm wrong.

I see something like this:

The following incident occured:

Start time: Wed Sep 13 16:22:13 2006

End time: Wed Sep 13 16:22:13 2006

Fired Rule Id: 183333

Fired Rule: System Rule: DoS: Network - Attempt

Incident Id: 593670234

For more details about this incident, please go to:

etc....

-randy

I stand corrected ... it is the SMS messages that don't show any details of significance.

wasn't aware of that - I guess the ability to customize any alert type would be nice (not just email)