Skip to main content

Alerts

In order to receive alerts a user needs to set up their personal alerts as described in Configuring personal alerts.

In order to send alerts to various recipients, configure alerting rules as described in Configuring alert rules

Configuring personal alerts

Use the personal alerts configuration screen to set up alerts that you will receive via direct messages. Configure and enable this under the User icon in the upper right, select User Settings | Integrations. Any alert that is sent to the "All Users" channel will go to you CSPM Alerts channel(s) that you enable (Email, Slack, Teams). You will need to follow the instructions to your authorize Slack or Teams identity to Cloud Defense. You can also enable and disable the daily summary from this screen.

Configuring alert rules

You can configure and create alert rules under Findings | Alerts. Create new rules here to alert on specific findings or events. For example, you want to alert "All Users" - the default target - for Critical and High findings in Prod Environments. You can also target specific users or channels.

Alert destinations

  • Slack: install the Cloud Defense app for Slack
  • Microsoft Teams: sideload the Teams app and connect it to your team
  • Amazon SNS: the message Cloud Defense sends to an SNS topic, and how to parse it