IBM QRadar SOAR

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Email notification condition issue on close an incident

    Posted Tue November 26, 2019 07:00 PM
    Hi all

    I would like to make a concrete/specific notification (match a condiction field on an incident) and make a "close incident" different from default when status is changed to closed applying  an additional condition.

    Is is possible or will disturb on the generic close condition for notification? I am not able to get it run.

    Is is possible to see a log for notification matches?
    Where can we see the smtp logs for sending the notifications? 

    Cheers, and thanks for sharing
    Oscar

    ------------------------------
    Oscar López
    ------------------------------


  • 2.  RE: Email notification condition issue on close an incident

    Posted Wed November 27, 2019 08:09 AM
    Are the default notifications being sent out? That will ensure that it is not an SMTP issue.

    Unfortunately there are no logs about notification matches.

    It would help if can post a screenshot with the notification definition you have set up.

    Another thing is that the person that caused the notification to be generated won't receive it (otherwise they would receive notifications for everything they did). So make sure you are testing with two different users.

    ------------------------------
    Ben Lurie
    ------------------------------



  • 3.  RE: Email notification condition issue on close an incident

    Posted Tue December 03, 2019 12:58 PM
    Hi Ben,
    Thanks for answering, we will test again.
    Definitively this could be the reason, the person that caused the notification to be generated won't receive it 
    Best regards
    Oscar

    ------------------------------
    Oscar López
    ------------------------------



  • 4.  RE: Email notification condition issue on close an incident

    Posted Wed December 04, 2019 06:56 AM
    Hi Ben

    A log on SMTP will help a lot
    >Unfortunately there are no logs about notification matches.

    The issue is that we are not receiving the notifications on close when a particular code is set to a value. Default on close notification are not beeing received too.

    Best regards
    Oscar




    ------------------------------
    Oscar López
    ------------------------------



  • 5.  RE: Email notification condition issue on close an incident

    Posted Wed December 04, 2019 09:41 AM
    I set up this test notification on incident close:



    I created an incident, assigned a different user as a member. I then closed the incident and the other user received an email.


    ------------------------------
    Ben Lurie
    ------------------------------