NOTIFICATION WORKFLOW Flashcards

1
Q

How to configure custom alerts to notify individuals about policies

A

-Click “Preview Alert” next to template you’d like to configure
-Enter search parameters, then run search.

     -Required fields cannot be set to “*” 
     -Fields with an asterisk in name support up to 50 comma – 
      separated values
     -Fields should not contain “$”
     -When satisfied, click “Configure Alert” 

-Set Alert Email Recipients, Alert Email Subject, Severity, Alert Email Body, and select if you’d like a preview of alert results included in email. If need to send a custom alert, separate with commas

  • Click “Schedule alert”
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a custom alert?

A

-Custom alerts are configured email alerts using predefined templates, user is notified about specific activity in environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How to create a custom alert?

A
  • Creating Custom Alert – 3 steps:

o Choose template you’d like to configure
o Preview search results
o Schedule the alert

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the available templates for custom alerts?

A

Available templates:
-Sensor entering RFM
-RTR Session Initiation
-Mobile Host Detections
-Analyst Contained a host
-Analyst repeatedly fails login
-OS Security Settings (IT Security Ops – Discover)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Do custom alerts run at a set interval?

A

YES, Custom Alerts run at a set interval

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the requirements needed to create a custom alerts?

A

-Falcon Admin (create/edit workflows, and view workflow audit/activity logs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What happens when an alert finds results?

A

–Sends an email to specified recipients

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does previewing alerts do?

A

-Previewing results helps see what results are found before you schedule the alert – adjust parameters as needed until satisfied with activity being found

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can the interval ever be changed?

A

The interval can’t be changed, because it runs in real time. When multiple results are found, they are sent in a singular email

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Why does an alert email its results instead of generating a new detection?

A

-Doesn’t generate a new detection so user can be notified about activity when not logged into Falcon console

How well did you know this?
1
Not at all
2
3
4
5
Perfectly