3 Replies Latest reply on Nov 16, 2016 3:14 AM by abanaru

    Creating Custom Alarm for Malicious file transfers


      I have created one alarm to trigger if any "infected" or "untrusted" file transfer happens.

      Condition: Field Match[ Event Subtype IN Infected OR Event Subtype IN untrusted ]

      Devices: ATD

      I am getting events in the dashboards but they are not triggering any alarms. Is there any mistake?