Configuring AMP for Networks Alerting

You can configure the system to alert you whenever any malware event, including a retrospective event, is generated by AMP for Networks (that is, a "network-based malware event" is generated.) You cannot alert on malware events generated by AMP for Endpoints ("endpoint-based malware events.")

Before you begin

  • Configure a file policy to perform malware cloud lookups and associate that policy with an access control rule as described in Access Control Overview.

  • You must have the Malware license to configure these alerts.

Procedure


Step 1

Choose Policies > Actions > Alerts.

Step 2

Click Advanced Malware Protections Alerts.

Step 3

In the Alerts section, choose the alert response you want to use for each alert type.

Tip

To create a new alert response, choose New from any drop-down list.

Step 4

In the Event Configuration section, check the check boxes that correspond to the alerts you want to receive for each malware event type.

Keep in mind that All network-based malware events includes Retrospective Events.

(By definition, network-based malware events do not include events generated by AMP for Endpoints.)

Step 5

Click Save.