Security Compliance
Create a FIM rule to get email notifications in SEM
This article provides steps to get email alerts when a third-party accesses folders or certain folders monitored by FIM for a specific node agent.
First published date
Last published date
Overview
This article provides steps to get email alerts when a third party accesses folders, or certain folders monitored by FIM, for a specific node agent.
In your SEM environment:
- An agent with a FIM connector is enabled
- The current event is File Read
- Events are processing into the system correctly
Product section
Resolution
Create a Rule:
This rule will monitor the directory specified above with the Tool Alias as FIM.
SEM Flash console
- Log in to your SEM web console.
- On the SEM menu bar, navigate to Build > Rules.
- On the upper right of the Rules pane, click the plus (+) sign to open the Rule Creation page.
- In the search box in the left panel, enter FileRead.
- Drag EventInfo and ToolAlias to Correlation box.
Correlation should appear similar to the following:
FileRead.EventInfo = *c:\gentkeys\* FileRead.ToolAlias = FIM File and Directory
- Expand the Actions group, and then drag the Send Email Message into the Actions box. The Action box must be assigned the correct recipients of the alert.
- Leave the Correlation Time as it is.
- Save the rule, and then click Activate Rule on the upper-right corner of the Rules page.
- In the SEM Events Console, click the Rules tab.
- On the rules toolbar, click Create new rule.
- In the Rule Values search box, enter FileRead.
- Under FileRead fields, drag EventInfo and ToolAlias into the rules builder.
Correlation should appear similar to the following:
FileRead.EventInfo = *c:\gentkeys\* FileRead.ToolAlias = FIM File and Directory
- Click Next.
- Complete the Details and actions, and include Send Email message as an action. Ensure the correct recipients are added.
- Ensure the rule is enabled, and then click Create.