SecureTrack Notifications

Overview

This topic describes the SecureTrack notifications that administrators can configure and distribute:

  • Policy change notifications

  • Aministrative alerts

  • Heartbeat notifications

  • Audit trail messages

These notifications report on changes to monitored device policies, on user activity in SecureTrack, and on the status of the SecureTrack license and device connectivity.

To monitor the health of the TOS cluster itself, use TOS Monitoring. TOS Monitoring tracks CPU, memory, and disk usage, database status, and deployment status for central and remote collector clusters. You set thresholds and severity for each notification, and you can choose to be notified again when the system returns to normal. TOS Monitoring sends notifications by email, syslog, SNMPv2, or SNMPv3.

Notification types and methods

The following table summarizes the notification types and the methods available for each type.

From TOS 5.3, syslog notifications can be sent using TCP or UDP. For TOS 5.2 or earlier, syslog notifications can only be sent using UDP.

Notification type

Description

Notification methods

Policy change notifications

Real-time information on changes to monitored firewall policies

SNMP traps, syslog

SecureTrack administrative alerts

Problems with the SecureTrack server or appliance, such as license status and device connectivity

Syslog, email

SecureTrack heartbeat

There is a known issue preventing SecureTrack from sending heartbeat notifications.

-

SecureTrack audit trail

Username and time for the events listed in the audit trail

Syslog

Policy change notifications

These notifications provide real-time information on changes to monitored firewall policies, similar to the information provided in the New Revision report.

Policy Change Notifications

You can send these Policy Change Notifications as follows:

  • Send by SNMP Traps: SNMP Notifications are sent to the SNMP Server configured here:
    • SNMP Server: Configure the IP address of the SNMP server to which SecureTrack should send Policy Change SNMP Traps.
    • SNMP Community: Choose the SNMP Community string, which will be used in the Policy Change SNMP traps. The community string is often used as a method of easy identification and classification of different SNMP traps.
    • The OID for the SNMP trap is as follows.

      Name

      OID

      Type

      Access

      Description

      stEvent1.3.6.1.4.1.21834.1.1.5 DisplayString Not accessibleThe event monitored by SecureTrack
  • Send by syslog: Policy Change Notifications are sent to the server configured under Configuring Servers.

SecureTrack administrative alerts

These alerts notify administrators of the following types of problems with the SecureTrack server or appliance:

  • License status
  • License usage
  • Device connectivity between TOS and the monitored device

You can send administrative alerts by:

  • Send by syslog: Sends alerts to the preconfigured syslog server.
  • Send by email: Sends alerts to the SecureTrack Administrators selected as Recipients using the preconfigured SMTP server.

  • See Configuring Servers.
  • SecureTrack heartbeat

    There is a known issue preventing SecureTrack from sending heartbeat notifications

    SecureTrack audit trail

    When you select Send by syslog, SecureTrack sends syslog messages to the configured syslog server with the username and time for the events listed in the audit trail.

    The areas of SecureTrack that are audited are:

    System Configuration

    Device Monitoring, Analysis and Reporting

    • User authentication
    • Device management
    • License management
    • Plugin and domain management
    • System configuration
    • User management
    • Policy comparison
    • Revision and rules metadata
    • Topology management
    • Zone management
    • Automatic policy generator jobs
    • Report configuration and generation
    • Repository

    Each action is listed with:

    • Date and time of the action
    • Username of the user that did the action
    • IP address of the host from which the action was done (automatic actions, such as scheduled reports, are listed without a user IP address)
    • Category or feature area that the action belongs to
    • Type of action, such as add, remove, modify, or generate report
    • Type of object and object name to which the action was done
    • Description of the action

    How do I get here?

    SecureTrack > Admin > Configuration > Notifications