Like reports, alerts are configured using FlowTraq Client, and like reports, the list of alerts is stored by FlowTraq Server. Also, FlowTraq Server is responsible for generating notifications. This means FlowTraq Client does not have to running in order for alert notifications to be generated; in other words, if you set an alert and then close FlowTraq Client, notifications will still be generated whenever the alert's condition is met.

To configure an alert, take the following steps.

  1. Access the "Alert Editor" window. There are two ways to access it:

  2. On the "Description" tab, title your alert and, optionally, provide a brief description.

  3. On the "Filter" tab, set the session filter you would like to be applied when testing for the alert condition.

    [Tip]Tip

    If you accessed the "Alert Editor" window from a Workspace, the session filter you specified there will be carried over into Alert.

  4. On the "Threshold" tab, set the condition on which to generate a notification by using the controls to fill in the blanks of the sentence displayed in the window:

    [Tip]Example

    Complete the "Threshold" tab as follows to cause alert to be raised when ever a host contacts more than one hundred unique other hosts in an hour: Trigger an alert when the number of Unique Hosts for any one Host exceeds 100 over interval One Hour.

    Now go back to the "Filter" tab and set a filter of Server port is any of: 22 to alert only if a host contacts more than one hundred other unique hosts using the SSH protocol.

  5. Click "OK" and the alert will be configured.