Health event external notifications
Firewall Management Center uses separate configurations to detect a health condition and notify an external system about it.
A health policy defines what Cloud-Delivered Firewall Management Center monitors and which conditions produce a health event. An alert response configuration defines how Cloud-Delivered Firewall Management Center communicates with an external destination, such as an email server. The monitor alert rule configuration connects the health policy and alert response by specifying which health events should trigger a particular alert response.
How the configurations work together
These steps describe how you configure external notifications for health events and how Cloud-Delivered Firewall Management Center processes the health event.
-
Configure and apply the health policy: A health policy enables health modules and defines the criteria used to assess appliance health.
For example, a health policy can enable the Memory Usage module and define Critical thresholds.
Apply the health policy to the appliance, including the Cloud-Delivered Firewall Management Center when you want to monitor Cloud-Delivered Firewall Management Center resources.
-
Configure the alert response: An alert response defines how and where Cloud-Delivered Firewall Management Center sends the external notification. Depending on the response type, the alert response contains the destination address, server or endpoint information, and other communication settings.
For example, an email alert response identifies the recipients, sender, and mail relay host that Cloud-Delivered Firewall Management Center uses to send the message.
For more information about alert responses, refer to Configuring external alerts with alert responses.
-
Configure the monitor alert rule: A monitor alert rule associates a health-event severity and one or more health modules with an alert response.
For example, a health monitor alert rule can specify:
Severity: Critical
Health module: Memory Usage
Alert response: Critical memory email
This means that when Cloud-Delivered Firewall Management Center generates a Critical event for the Memory Usage module, it invokes the associated alert response.
For more information about health monitor alerts, refer toHealth monitor alerts.
-
Cloud-Delivered Firewall Management Center generates a health event: Cloud-Delivered Firewall Management Center evaluates the enabled health modules according to the health policy and its configured run interval. When a health module evaluates an appliance and the result meets a configured condition, Cloud-Delivered Firewall Management Center generates a health event.
Note that a health event is an event log within Cloud-Delivered Firewall Management Center; it does not send an external notification by itself.
-
Cloud-Delivered Firewall Management Center matches the event and sends the notification: Cloud-Delivered Firewall Management Center evaluates the generated event against the configured health monitor alerts. If the event's module and severity match a monitor alert rule, Cloud-Delivered Firewall Management Center invokes the alert response associated with that rule and sends the notification to the configured external system.
Note | Health alerts can take approximately 5–6 minutes to be generated after the corresponding health event occurs. |