Create and Assign a Sending Policy for Alerts

Applies To: WatchGuard Advanced Reporting Tool and Data Control

Sending policies enable you to define how to send generated alerts. You can deliver alerts to servers, groups, or individuals either in real-time or at set intervals.

When you create a sending policy, you include the anti-flooding policy and delivery methods. For more information, see Create an Anti-Flooding Policy for Alerts and Configure Delivery Methods for Alerts.

Screen shot of WatchGuard EPDR, Advanced Visualization Tool, Alert Sending Policy tab

To create a sending policy, in the Advanced Visualization Tool:

  1. From the left pane, select Administration > Alerts Configuration.
  2. Select Alert Policies.
  3. Select Sending Policy.
  4. Click New Sending Policy.
    The New Sending Policy dialog box opens.

Screen shot of WatchGuard EPDR, Advanced Visualization Tool, Sending Policy dialog box

  1. In the Name text box, type a unique name for the sending policy.
  2. To automatically assign this policy as the sending policy when an alert does not have a sending policy, select the Set as Default Policy check box.
  3. From the Anti-flooding Policy drop-down list, select the anti-flooding policy you want to apply.
    For more information, go to Create an Anti-Flooding Policy for Alerts.
  4. In the schedule section, select the days of the week and the time period when the sending policy is active.
  5. From the drop-down lists, select a delivery type and delivery method.
    For more information, go to Configure Delivery Methods for Alerts.
  6. Click Add.
  7. Repeat steps 9 and 10 for each delivery method you want to add.
  8. Click Create.

Assign a Sending Policy to an Alert

After you create a sending policy, you can assign it to alerts on the Available Alerts tab.

Screen shot of WatchGuard EPDR, Advanced Visualization Tool, Available Alerts tab

To assign a sending policy to an alert:

  1. From the left pane, select Administration > Alerts Configuration.
  2. Select Available Alerts.
  3. To filter the list of alerts, use the All Categories and All Subcategories boxes.
  4. To further reduce the number of alerts in the list, enter keywords in the Filter box.
  5. From the list, select the alert you want to assign a sending policy to.
  6. In the Active Policies column, click Screen shot of the sending icon.
    The Sending Policies dialog box opens.

Screen shot of WatchGuard EPDR, Advanced Visualization Tool, Sending Policy dialog box

  1. Select the sending policies you want to assign to the alert.
  2. Click Apply.

Edit and Delete Sending Policies

You can edit or delete an existing policy on the Sending Policy tab.

To edit a sending policy, in the Advanced Visualization Tool:

  1. From the left pane, select Administration > Alerts Configuration.
  2. Select Alert Policies.
  3. Select Sending Policy.
  4. From the list of policies, click Screen shot of the ellipsis icon in the row for the policy you want to edit.
  5. Select Edit.

Screen shot of WatchGuard EPDR, Advanced Visualization Tool, Sending Policy dialog box

  1. To automatically assign this policy as the sending policy when an alert does not have a sending policy, select the Set as Default Policy check box.
  2. From the Anti-flooding Policy drop-down list, select the anti-flooding policy you want to apply.
  3. In the schedule section, select the days of the week and the time period when the sending policy is active.
  4. From the drop-down lists, select a delivery type and delivery method. Click Add.
  5. To delete an existing delivery type and method, in the row of the method you want to delete, click Screen shot of the Delete icon. .
  6. Click Update.

To delete a sending policy, in the Advanced Visualization Tool:

  1. From the left pane, select Administration > Alerts Configuration.
  2. Select Alert Policies.
  3. Select Sending Policy.
  4. From the list of policies, click Screen shot of the ellipsis icon in the row for the policy you want to delete.
  5. Select Delete.
    A Warning dialog box opens.

Screen shot of WatchGuard EPDR, Advanced Visualization Tool, delete alerts dialog box

  1. Click Delete.

Related Topics

About Real-Time Alerts in the Advanced Visualization Tool

Create Alerts in the Advanced Visualization Tool