Submit a ticketCall us

Solarwinds & Cisco Live! Barcelona
Join us from the 29th of January to the 2nd of February at Cisco Live 2018 in Barcelona, where we will continue to show how monitoring the network with SolarWinds will keep you ahead of the game. At our booth (WEP 1A), we will demonstrate how SolarWinds network solutions can help. As a bonus, we are also hosting a pre-event webinar - Blame the Network, Hybrid IT Edition with our SolarWinds Head Geek™, Patrick Hubbard on January 24th - GMT (UTC+0): 10:00 a.m. to 11:00 a.m. There's still time to RSVP.

Home > Success Center > Log & Event Manager (LEM) > Create FIM Rule to get email notifications

Create FIM Rule to get email notifications

Table of contents
Created by Christine Magbuo, last modified by MindTouch on Jun 23, 2016

Views: 1,608 Votes: 0 Revisions: 6

Overview

This article provides steps to get email alerts when a third-party accesses folders or certain folders monitored by FIM for specific node agent.

Environment

All LEM versions

  • Agent with FIM connector enabled
  • Current event is File Read
  • Events is coming in fine and will create Rule based on File Read events

Steps

Create a Rule:

1. Log in to your web console.  

2. Go to Build, and then click Rules.

3. Click  Expand (+). The Rule Create window will appear.

4. Click Events > Search in the left pane. 

5. Enter File read in the Search box. 

6. Drag EventInfo and ToolAlias to Correlation box.

Correlation should appear similar to the following: 

FileRead.EventInfo = *c:\gentkeys\*
FileRead.ToolAlias = File File and Directory

 

Note: The Action box must be assigned the correct recipients of the alert. 

This rule will monitor the directory specified above with the Tool Alias as FIM. 

 

7. Leave the Correlation Time as it is.

8. Save the Rule and click Activate Rule on the upper right corner of the Rules page.

 

 

Last modified

Tags

Classifications

Public