Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Way to limit # of email alerts per PC using Alert Manager?

Status
Not open for further replies.
Sep 16, 2003
76
0
0
US
Hello All,


I'm in the process of testing Alert Manager v4.7 and I'm configuring the clients to email the admin staff when a virus is detected. The concern I have is that at times the database has listed 500+ incidents from one machine in just a few hours (Nachi was bouncing back and forth between two machines...their virus DATs were up to date, but the security holes were not patched). We have 6 admins here and if each of them are receiving email alerts that would add up to 3000 emails in just a few hours. Is there some way to configure Alert Manager so that it will only email one time per machine per day or something like that? That sounds confusing, what I'm trying to say is that I would like to have it configured so that if PC "A" gets infected, I only want one email about it per day even if it gets infected by another virus or whatever. From the first email I'll already be advised that attention is needed for that PC... Anyone?


Thanks,


Jay
 
That would be great, but say you have a virus outbreak happening at the moment and you only receive ONE ALERT, you won't have an idea of the magnitude of the infection until much later.

AVChap
... been there, done that, made that mistake too, see where I am now.
 
AVChap - Thanks for the reply!


My thought is that if PC "A" tells me it's infected, fine I'll go service it as needed ASAP -I don't need to hear about 500 times. If an outbreak happens I would like to think it would become apparent if multiple machines start emailing me, even if it's only one email per PC... Just my thoughts...

Thanks again,


Jay

 
As I said, if you only get one alert per PC, it would cloud your judgement as to whether you'll service it immediately (it's only one infection right? :)) but if you get a lot, then it would require more attention.

Just my 2cents worth.

AVChap
... been there, done that, made that mistake too, see where I am now.
 
I think this is a valid question. It's not a case of 'not realising' when an outbreak in present... I personally don't want the Nachi virus to cause McAfee to hammer my SMTP server with thousands of emails!

This happened to me and our SMTP server crashed because McAfee on 200 computers kept sending emails to the administrators. An 'Outbreak' email that states how many infecteds it detected would be much better.

-=L9NUX=-

-= There's no place like 127.0.0.1 =-
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top