I use EPO 4.6
Yes, you can. There are a number of ways you can configure it. I would create an automatic response based on the criteria you set for the type of event you want to see.
Can you please explain to me step by step how can I do it? please
Yes I find it but after I have to configure a lot of parameters....any suggestion??
You don't ned to configure new parameters, just only set the action at the end (for example send an e-mail) and it will work.
After this you can change variables used in the mail sent but that will be the next step
On the following fields, do this:
Call it whatever you want
Status is "enabled"
Make sure the event is "ePO notification events" and event type is "threat"
"Detecting product" is set as VIRUSCAN8700 or VIRUSCAN8800 (8.7 or 8.8 depending on what you are running)
"Threat Action Taken" is set as "Does not equal" and then you can select "Cleaned", as well as "Deleted"
For a good measure, you may want to play around with the "Threat Handled" property as well
This section may take some tuning, as it is the most important. You may not get what you are seeking right off the bat, but you can tweak it to suit your needs.
For this section personally, I would just set the Detecting product, and Threat Handled field to "Equals" and "false".
Leave this as "Trigger this response for every event" unless you want to throttle the responses.
Click the drop down and select "Send Email", from here you can fill in the rest of the blanks.
Just summarizes the whole task. Again this task can be modified several different ways.