You can create a notification rule that emails a recipient list whenever a new threat briefing is published or automatically restored. Briefings are automatically restored if they are updated with content changes or new detections.
Before you begin
- Users must be granted access through the Detections Access Control global policy and have full-write privileges or higher.
- The ExtraHop system must be connected to ExtraHop Cloud Services to send notifications through email.
- Email notifications are sent from email@example.com. Make sure to add this address to your list of allowed senders.
- Log in to the ExtraHop system through https://<extrahop-hostname-or-IP-address>.
- Click the System Settings icon and then click Notification Rules.
- Click Create.
- Type a unique name for the notification rule in the Name field.
- In the Description field, add information about the notification rule.
- In the Event Type section, select Threat Briefing.
- Specify individual email addresses, separated by a comma.
- In the Options section, click the Enable notification rule checkbox to enable the notification.
- Click Save.