I am creating a new correlation rule, it fires if no events comes within 3 hours depending on the username in multithreading , then i connect this alert with email output action, the problem when it is fired the email does not have the information like the username, address... etc.
Try to change Maximum lenght from (default 1024) to 8000 (not 8192) in
Alerts->Alert Configuration->Output Actions->Manage Output Action Templates and use Shoft or Long format/Most Common Fields depending what you want.
The problem is that the alert fires when no event comes, so there is no information to display in the email, i have five user names i want to check if no event comes according to this user name in 3 minutes, so i want to display in the email which user name that does not create the event, but the email comes empty or just the subject and the bode i wrote in the output action, what could i do ?
Hi there... I wish I was replying with something positive, but in my experience with enVision output actions, customization is a myth. I've created my own templates and been very specific about what should be in the email, but enVision either puts everything or not enough. I've had two cases open about it, and "engineering" was never able to give me a solution. Because I work in a compliance context, and certain information my not be transmitted over the internet, my email alerts have very little in them and are just a message to check task triage or the Alert History.
When a correlation rule fires, we have the information about the event message that satisfies the rule will be displayed with details in the CSV file..
But, here the rule itself is for "No events in 3 hours". That means you will not have any event message in the .CSV file when your alert triggers.
Hope this helps!!!!!