Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: Why Does an Alert Description Differ Between Console and Email Notification?

Carbon Black Cloud: Why Does an Alert Description Differ Between Console and Email Notification?

Environment

  • Carbon Black Cloud Console: All Versions
  • Endpoint Standard Sensor: All Supported Versions
  • Windows: All Supported Versions
  • MacOS: All Supported Versions

Question

Why does the description for an alert differ from an email notification to the web console?

Answer

If a notification is sent on an alert that meets the criteria( for example, "Threat" >= 5), and another alert happens later that analytics bundles with the same threat, The description of the threat is updated in the web console to reflect the latest/most severe activity, but the back end doesn't send out an additional email. 

Additional Notes

Analytics intentionally groups many alerts, in the same time window, on the same device into a single threat for the customer. Whenever an alert description is updated, additional emails are not sent. This is intended behavior to reduce notification noise for the customer.
 

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-13-2020
Views:
193
Contributors