Notification rules in the DOC
Configuration: DOC -> Analytics -> Events -> Notification rules
You can define notifications for all events that the DriveLock Agent reports to the DriveLock Enterprise Service (DES) via e-mails to one or more recipients. For example, if you want to be notified that DriveLock Agent has detected a virus on an agent, you can associate the corresponding event with an action. For this you will create a notification rule.
Please do the following:- Once you have assigned a name, choose the events you want to be notified about. Click Select... in the Selected events section. For example, select Event 684: Microsoft Defender detected a threat.
- The notification rule is enabled by default. You can uncheck Enable if you want to temporarily disable the rule but not delete it.
Under Actions , click Create new action and enter the appropriate information in the dialog. If you click Configure e-mail templates, you can create different templates with custom texts, either in English or German.
If you have already created actions, you can select them again and again (even in different rules) and have them sent to the appropriate recipient groups.
Configuring the e-mail server
To configure an e-mail server to receive the notifications, click the button and select Configure e-mail server.
The mail server is configured in the Tenant settings under e-mail and mail server.
The default setting is DriveLock, with e-mails sent via the DriveLock mail server. This option works only for Managed Security Services in the cloud. Alternatively, you can select SMTP if you are using DriveLock On-Premise. In this case, you must specify the configuration of your SMTP server yourself.