Skip to main content
Question

Unusual File Activity not emailing.


Forum|alt.badge.img+8

Hi guys,

 

I was testing alerting yesterday & I dropped an eicar test file on one of my test servers that I current backup using ver 11.32

 

I got no alerts emailed to me but I did get the alerts in the event viewer

69:59    Possible threat found on client [xyztestfs] [count - 3]. Check Unusual File Activity report for more detail.

 

I checked my setup and I can see the alert below, if I click test an email gets sent to me.

I also have alerts setup to mail me on the following Alert Criteria: 
(Event Code equals to 7:211 OR 7:212 OR 7:293 OR 7:269 OR 14:336 OR 14:337 OR 69:59 OR 7:333 OR 69:52) but still never got a mail.

I do alerts from the above criteria from other servers I backup. 

Any help here would be grateful.

 

4 replies

Forum|alt.badge.img+6
  • Byte
  • 28 replies
  • October 10, 2024

Any errors that stand out in sentalerts.log?


Forum|alt.badge.img+8
  • Author
  • Byte
  • 44 replies
  • October 10, 2024

nope, can only see the mail alerts that were received by myself


Forum|alt.badge.img+6
  • Byte
  • 28 replies
  • October 10, 2024

In your screenshot, you have an email under the “CC” but do you have an email address configured for the “TO” portion?


Forum|alt.badge.img+8
  • Author
  • Byte
  • 44 replies
  • October 10, 2024

Yes, there is a distribution list address in the To. As mentioned, if I hit test both addresses get the test mail.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings