Skip to main content
ede_pfau
SuperUser
SuperUser
October 23, 2014
Solved

filter on events reported in AlertEmail

  • October 23, 2014
  • 2 replies
  • 4355 views

hello fellows,

 

dumb question actually: sometimes I target alertemails of customer firewalls to me. Now, is there an option to filter which events get reported? Like in 'config log <dev> filter'? I'd love to cut out these webfilter messages which occur in hundreds per day.

 

Setting the alert level higher doesn't work for this as 'status=blocked' is at the 'warning' level, as are other more serious events.

    Best answer by Jeff_FTNT

    You may try ways to restrict Alert email for Webfilter event.

    ### Based on event

    config alertemail setting     set filter-mode category     set webfilter-logs disable     set admin-login-logs enable end ### Based on event log level, change interval to 1440min/1 day  for  "warning" level event. config alertemail setting     set filter-mode threshold     set warning-interval 1440 end

     

    Thanks.

    2 replies

    Jeff_FTNT
    Staff
    Jeff_FTNTAnswer
    Staff
    October 23, 2014

    You may try ways to restrict Alert email for Webfilter event.

    ### Based on event

    config alertemail setting     set filter-mode category     set webfilter-logs disable     set admin-login-logs enable end ### Based on event log level, change interval to 1440min/1 day  for  "warning" level event. config alertemail setting     set filter-mode threshold     set warning-interval 1440 end

     

    Thanks.

    ede_pfau
    SuperUser
    ede_pfauAuthor
    SuperUser
    October 24, 2014

    Thanks Jeff, I thought it was a dumb question, so obvious...