Views:

Set up and manage your endpoint security alert notifications and watchlist.

Important
Important
  • Endpoint Security Policies (unified assignment) is a "Pre-release" feature and is not considered an official release. Please review the pre-release disclaimer before using the feature.
  • This feature is not available in all regions.
  • The steps in this article configure both alerts which appear in Endpoint Alerts and alert notifications sent to recipients in your organization.
The Endpoint security alerts notification settings manage both the alerts sent to your recipients and the alerts displayed in Endpoint Alerts. For more information about Endpoint Alerts, see Endpoint Alerts.
Endpoint Alerts requires enabling and setting up Endpoint security alerts in Notifications. At least one recipient is required to set up the alert feature. Once configured, any Trend Vision One user in your company with permission to view Endpoint Alerts can see the alerts on your watchlist.

Procedure

  1. In the Trend Vision One console, go to AdministrationNotificationsAlerts.
  2. Click Endpoint security alerts.
    The Alert settings appear.
  3. To enable notifications, click On.
    Important
    Important
    You must enable notifications to start sending alerts to Endpoint Alerts.
  4. Configure the Endpoint alert watchlist.
    1. Click Configure watchlist.
    2. In the Endpoint Security alerts screen, select alerts in the Available security alerts list you want to monitor and click the selector icon (simulationsRightArrow=20220525102311.png) to add to the watchlist.
    3. To remove alerts from the watchlist, select the alerts in the Selected alerts list you do no want to monitor and click the remover icon (simulationsLeftArrow=20220525102211.png).
    4. Once you have configured the Selected alerts you want to monitor, click Apply.
      Important
      Important
      The watchlist applies to all Trend Vision One users who have permission to view Endpoint Alerts. Users cannot individually customize the watchlist for their own view.
      Clicking Apply does not save your settings. You must click Save for the Alert settings.
  5. Specify the Frequency of notifications.
  6. To automatically dismiss alerts in Endpoint Alerts, select If still active after 3 days.
  7. Configure the recipients for the notification.
    Note
    Note
    Recently created Trend Vision One accounts might not immediately appear as an available recipient.
    To configure a recipient group, click SettingsRecipient group list in the main Notifications list view.
    1. To send notifications by email, click the Email tab and specify email addresses, Trend Vision one accounts, or email groups to receive the notification.
      To send a test email, click Send test message. You can specify whether to Send only to newly added recipients or Send to all recipients.
    2. To send notifications by webhook, click the Webhook tab and specify which webhooks or webhook groups to receive the notification.
      If your webhook is not listed, create a new webhook connection by managing webhooks in the Webhook List.
    3. To send notifications to users by the Trend Vision One mobile app, click the Mobile tab and specify the Trend Vision One user accounts or mobile groups to receive the notification.
      To send an installation link for the mobile app, click Send Mobile App Installation Link. You can specify whether to Send only to newly added accounts or Send to all accounts.
  8. To control which notifications are sent to your recipients, configure recipient groups to receive notifications based on the type and severity of endpoint alerts.
    Note
    Note
    The following steps apply to each notification type. Repeat the steps as needed to configure your email, webhook, and mobile notification settings.
    Recipients or webhooks not added to a group receive all notifications by default.
    1. For email and mobile users, enable Notify recipients based on endpoint alert.
    2. For webhooks, enable Send webhook notifications based on endpoint alert.
    3. For each notification method, click Select group.
    4. Select a Group name.
    5. Select which Endpoint alerts to send notifications.
    6. Select one or more Alert severity levels to send notifications.
      Recipients only receive alerts for the selected alert severity. If you only select Low, the group does not receive higher severity alerts, and does not receive Informational alerts. You can select the following severity levels:
      • Critical
      • High
      • Medium
      • Low
      • Informational
    7. Click Save.
  9. Once you have configured the notification methods you want to use, click Save.