Alerts

A description of alerts management in a Central Management Console (CMC).

Alerts management in the Central Management Console (CMC) is similar to alerts management in a sensor. However, in the CMC, you can have all the alerts, from all the sensors, in one centralized place.

In a sensor, you can create a query, and therefore an assertion, that includes all the nodes, or links etc., for your complete infrastructure. You can create a Global Assertion. This is one or more groups of assertions that can be propagated to all the sensors. The CMC has control of these assertions, and sensors cannot edit or delete them.

It is possible to configure the CMC to forward alerts to a security information and event management (SIEM) without the need to configure each sensor. For more details, see Data integration.