IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: Why Does an Alert Description Differ Between Console and Email Notification?

Carbon Black Cloud: Why Does an Alert Description Differ Between Console and Email Notification?

Environment

  • Carbon Black Cloud Console: All Versions
  • Endpoint Standard Sensor: All Supported Versions
  • Windows: All Supported Versions
  • MacOS: All Supported Versions

Question

Why does the description for an alert differ from an email notification to the web console?

Answer

If a notification is sent on an alert that meets the criteria( for example, "Threat" >= 5), and another alert happens later that analytics bundles with the same threat, The description of the threat is updated in the web console to reflect the latest/most severe activity, but the back end doesn't send out an additional email. 

Additional Notes

Analytics intentionally groups many alerts, in the same time window, on the same device into a single threat for the customer. Whenever an alert description is updated, additional emails are not sent. This is intended behavior to reduce notification noise for the customer.
 

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-13-2020
Views:
407
Contributors