Configurations Supporting Alert Responses
After you create an alert reponse, you can use it to send the following external alerts from the Cisco Defense Orchestrator.
|
Alert/Event Type |
For More Information |
|---|---|
|
Intrusion events, by impact flag | |
|
Discovery events, by type | |
|
Malware and retrospective malware events detected by AMP for Networks ("network-based") | |
|
Correlation events, by correlation policy violation | |
|
Connection events, by the logging rule or default action (email alerts not supported) | |
|
Health events, by health module and severity level |