截屏视频帮助

Responce rule need filter of successfully executed

创建时间: 02 3 月 2012 | 2 条评论
kishorilal1986 的图片
0 同意
0 不同意
0 0 Votes
Login to vote

Hi guys,

This idea came in mind while I was executing responce rule for auto escalation.

  • I suggest / recommend to symantec to include this filter to sort out for which incidents responce rule is executed.
  • As we manually executing preconfigure response rules for automated escalation alert mail but when we apply for group of incidents then it is difficult to find out which is successfully executed and which is not.
  • For this currently we are checking individually incidents for sucessful mesage sent.

Thanks & Regards

Kishorilal

评论 条评论跳转至最新评论

DLP Solutions2 的图片

Kishorilal,

What you can do as part of the Response Rule is to alo have it update or edit a Custom Attribute field that says, "executed" or somthing like that.

You can then filter using that field to see what was run or not.

Please make sure to mark this as a solution

to your problem, when possible.

+2
Login to vote
Keith Reynolds - ExchangeTek 的图片

The above is the way to go...I typically include a custom attribute called "User Notified" and "Manager Notified", and set this value to "Yes" when the response rule is executed.  It's great for reporting as well, as I can now tell, by user and policy, how many times a particular user has been notified.

~Keith

0
Login to vote