Alerting options
In the third node, 'Alerting options', you can specify the GFI LANguard S.E.L.M. Alerter Agent options. The Alerter Agent is the service that will notify you when it encounters high-risk events.
In this dialog you must specify the administrator email address, the SMTP server name and the port.

The Alerter properties
When you will receive an administrative alert email, you will be presented with both the original details of the event as well as extended information explaining to you what may have caused that event and how to deduce whether that event indicates an intruder or not.
Specifying which events to be notified on
In the "Notifications" page of this dialog, you can indicate about which events you want to be emailed. We recommend that you select either Critical or Critical and high to start off. Especially during the first week we recommend you collect data first. Then close off security holes and only after that enable email alerts in order not to fill up your inbox.
You can enable/disable email notification security levels at any operational time and you will not require re-starting the GFI LANguard S.E.L.M. alerter agent service for the new changes to take effect.

The Alerter properties – email notifications page
See chapter 'Security event categorization' to know what events are considered Critical, high, medium or low.
Notification Exceptions

Email notifications exceptions page
In this dialog you can specify exceptions for the administrative email alerts. For example, you might have administrators who frequently perform administrative operations outside of normal operational time. These actions could generate a lot of email notifications. You can configure LANguard S.E.L.M not to send alerts for these users, by adding the domain and user name in this dialog.
LANguard S.E.L.M. will still archive the event, however it will not send an email alert.
NOTE : For security reasons, the events generated will still be archived and viewable from the LANguard S.E.L.M. Event Viewer and from the reports.
|