Skip to main content

System Alerting Window

The System Alerting window is only available to administrators, enabling them to configure and manage all alerting avenues. Click Configuration > Alerts on the menu to open it.

Netwrix Threat Prevention System Alerting window

Threat Prevention can send alerts to recipients via email, to the Windows Event Log, and to SIEM products. Alerts are grouped into five types:

  • Security – Provides alerts on things that impact:

    • What data Threat Prevention collects
    • The ability to collect the data
    • Changes to who can access it
  • Operations – Provides alerts on internal operations of the product that a user doesn't directly influence

  • Configuration – Provides alerts on changes to general configuration settings

  • Analytics – Provides alerts when an analytic incident triggers. These alerts aren't available for Event Log alerts.

  • Policies – Provides alerts when a policy monitors or blocks an event. These alerts aren't available for Event Log alerts.

Email and SIEM Alert Notifications for Policy Events

You can enable email and SIEM alert notifications for policy events through:

In any case, you must first set the configuration through the System Alerting window. The Alerts Interface shows recent alerts in a centralized location.

Email and SIEM Alert Notifications for Analytic Incidents

You can configure email and SIEM alert notifications for Analytic incidents through the System Alerting window to send Ongoing Attack Alerts. In this case, Threat Prevention sends periodic reminders of an ongoing attack if it continues after the initial notification.

View the Alert Notifications

Threat Prevention generates notifications for the alerts you enable on the System Alerting window.

General Considerations

Consider the following:

  • Occasionally a Microsoft Security Bulletin impacting LSASS can interfere with the Agent instrumentation resulting in LSASS shutting down. The Agent is configured to monitor for an LSASS process termination shortly after a server reboot. The LSASS Process Terminated alert (Operations alert) triggers in this event and the Agent stops. As a result, all monitoring/blocking by that Agent stops. To resolve the issue, either upgrade to the latest version of the Agent or upgrade SI.ActiveDirectoryMonitor.dll - commonly known as ADMonitor DLL (recommended). See the Upgrade ADMonitortopic for additional information.

    info

    Activate an email notification for the LSASS process terminated alert. See the Enable the 'LSASS Process Terminated' Email Alert topic for additional information.

  • In addition to the LSASS process termination check, you can configure the Agent for a Safe Mode. In Safe Mode, the Agent records the version of the LSASS DLLs that it hooks into during installation. When you restart an Agent, it compares the DLL versions with the recorded list. If the versions don't match, the Windows AD Events monitoring module doesn't load. The Agent’s status in the Agents interface changes to Active (Modules Pending), and all Active Directory monitoring/blocking by that Agent stops. The 'Agent Started in AD Monitor pending mode' alert (Operations alert) triggers in this event. To resolve the issue temporarily, the Threat Prevention administrator should start the pending modules. See the Start Pending Modules topic for additional information. Netwrix also recommends upgrading SI.ActiveDirectoryMonitor.dll (commonly known as ADMonitor DLL) to resolve the issue permanently. See the Upgrade ADMonitor topic for additional information.

    info

    Activate an email notification for this alert. See the Enable Agent Started in AD Monitor Pending Mode Email Alert topic and the Agent Safe Mode topic for additional information.