No Alert notification from Device Security
416
Created On 05/06/24 02:40 AM - Last Modified 06/11/25 19:32 PM
Symptom
- No Alert notification
Environment
- Device Security
- Alert notification
Cause
The alert rule is defined with a AND on at least 2 "Change Event" conditions.
And the 2 selected "Change Events" are unlikely to occur at the same time.
For instance:
- risk level change event AND new device discovery
Resolution
Edit the rule details to avoid matching not possible situations.
Additional Information
Change Event list:
- IP change
- New Device Discovery
- New Profile Discovery
- New Vulnerability Discovery
- Offline Device
- Purdue Level Change
- Risk Level Change
- Subnet Change