Skip to content

Commit 3341ba1

Browse files
authored
Merge pull request #833 from flashcatcloud/sync/doc-cards-b17-test2
Sync to test: Zeek and Check Point SmartEvent push mode wording
2 parents 1244e2e + 6005755 commit 3341ba1

4 files changed

Lines changed: 4 additions & 4 deletions

File tree

‎en/on-call/integration/alert-integration/alert-sources/check-point-smartevent.mdx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ You can get the integration email address in either of two ways. **Choose the Em
3131
## Confirm the push mode in Flashduty
3232
---
3333

34-
SmartEvent sends one mail per event and no recovery mail, and the subject carries the event number (see [Mail subject format](#mail-subject-format)), so every mail is an independent event. Keep the Email integration's default push mode: each mail creates a new alert whose title is the mail subject and whose description is the mail body. No trigger or close rules are needed.
34+
SmartEvent sends one mail per event and no recovery mail, and the subject carries the event number (see [Mail subject format](#mail-subject-format)), so every mail is an independent event. Set the Email integration's push mode to the one that always triggers a new alert (the create page may preselect a different mode, so check it): each mail creates a new alert whose title is the mail subject and whose description is the mail body. No trigger or close rules are needed.
3535

3636
## In Check Point SmartConsole
3737
---

‎en/on-call/integration/alert-integration/alert-sources/zeek.mdx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ Get the integration email address in either of the two ways below. **In both cas
3232
## Configure the push mode in Flashduty
3333
---
3434

35-
Zeek notice emails only trigger; there is no resolve email, so no rules are needed to close alerts. Keep the email integration's default push mode, which creates a new alert for every email.
35+
Zeek notice emails only trigger; there is no resolve email, so no rules are needed to close alerts. Set the email integration's push mode to the one that always triggers a new alert (the create page may preselect a different mode, so check it), which creates a new alert for every email.
3636

3737
- The alert title is the email title, for example `[Zeek] SSH::Password_Guessing` (bracketed prefix plus the notice type)
3838
- The alert description is the email body, with the notice message, the source and destination addresses and ports of the connection, and so on

‎zh/on-call/integration/alert-integration/alert-sources/check-point-smartevent.mdx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ SmartEvent 的自动响应(Automatic Reaction)提供邮件、SNMP Trap、封
3131
## 在 Flashduty 中确认推送模式
3232
---
3333

34-
SmartEvent 每个事件只发一封邮件,没有恢复邮件,标题里带有事件编号(见下文 [邮件标题格式](#邮件标题格式)),每封邮件都是独立的事件。邮件集成保持默认的推送模式即可:系统为每一封邮件创建一条新告警,标题为邮件标题,描述为邮件内容。不需要配置触发和关闭规则。
34+
SmartEvent 每个事件只发一封邮件,没有恢复邮件,标题里带有事件编号(见下文 [邮件标题格式](#邮件标题格式)),每封邮件都是独立的事件。邮件集成的 **推送模式** 选择 **总是触发新告警**(新建集成时页面可能预选了其他模式,请确认):系统为每一封邮件创建一条新告警,标题为邮件标题,描述为邮件内容。不需要配置触发和关闭规则。
3535

3636
## 在 Check Point SmartConsole 中配置
3737
---

‎zh/on-call/integration/alert-integration/alert-sources/zeek.mdx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ Zeek 通过 Notice 框架把检测结果记为通知(notice),并可以用
3232
## 在 Flashduty 中配置推送模式
3333
---
3434

35-
Zeek 的通知邮件只有触发,没有恢复邮件,所以不需要按规则关闭告警,保持邮件集成的默认推送模式即可:每封邮件新建一条告警。
35+
Zeek 的通知邮件只有触发,没有恢复邮件,所以不需要按规则关闭告警,**推送模式** 选择 **总是触发新告警**(新建集成时页面可能预选了其他模式,请确认):每封邮件新建一条告警。
3636

3737
- 告警标题是邮件标题,例如 `[Zeek] SSH::Password_Guessing`(方括号前缀加通知类型)
3838
- 告警描述是邮件正文,包含通知消息、连接的源和目的地址与端口等

0 commit comments

Comments
 (0)