Cisco Cisco Web Security Appliance S670 User Guide

Page of 582
M A N A G I N G   A L E R T S
C H A P T E R   2 2 :   S Y S T E M   A D M I N I S T R A T I O N
 505
M A N A G I N G   A L E R T S
Alerts are email notifications containing information about events occurring on the IronPort 
appliance. These events can be of varying levels of importance (or severity) from minor 
(Informational) to major (Critical) and pertain generally to a specific component or feature on 
the appliance. Alerts are generated by the IronPort appliance. You can specify which alert 
messages are sent to which users and for which severity of event they are sent. Manage alerts 
using the System Administration > Alerts page in the web interface or using the 
alertconfig
 
command in the CLI.
Note — To receive alerts and email notifications, you must configure the SMTP relay host that 
the appliance uses to send the email messages. For information about configuring the SMTP 
relay host, see “Configuring SMTP Relay Hosts” on page 482.
Alerting Overview
The alerting feature consists of two main parts: 
• Alerts - consist of an Alert Recipient (email addresses for receiving alerts), and the alert 
notification (severity and alert type) sent to the recipient.
• Alert Settings - specify global behavior for the alerting feature, including alert sender 
(FROM:) address, seconds to wait between sending duplicate alerts, and whether to 
enable AutoSupport (and optionally send weekly AutoSupport reports).
Alerts: Alert Recipients, Alert Classifications, and Severities
Alerts are email messages or notifications containing information about a specific function (or 
alert classification) or functions such as a hardware or anti-virus problem, sent to an alert- 
recipient. An alert recipient is simply an email address to which the alert notifications are 
sent. The information contained in the notification is determined by an alert classification and 
a severity. You can specify which alert classifications, at which severity, are sent to any alert 
recipient. The alerting engine allows for granular control over which alerts are sent to which 
alert recipients. For example, you can configure the system to send only specific alerts to an 
alert recipient, configuring an alert recipient to receive notifications only when Critical 
(severity) information about the System (alert type) is sent. You can also configure general 
settings (see “Configuring Alert Settings” on page 511).
Alert Classifications
AsyncOS sends the following alert classifications:
Table 22-3 Alert Classifications and Components
Alert Classification
Alert Component
System
System
Hardware
Hardware