Email warnings on clients not working

Discussion in 'Other ESET Home Products' started by tanstaafl, Oct 13, 2010.

Thread Status:
Not open for further replies.
  1. tanstaafl

    tanstaafl Registered Member

    Joined:
    Apr 8, 2005
    Posts:
    207
    Hello,

    I'm trying to get this working so that the clients will all generate an email whenever there are any warnings, but can't get it working...

    The clients are all 4.2.35.0, and I'm using the Policy Manager via Remote Admin 3.1.15.

    Under 'Alerts and notifications' I am defining the following settings:

    SMTP server: smtp.example.com:587
    ^^^
    Attempting to define the port appears to be the problem, as if I remove the submission port (587), I get a reject in my logs (as it should - our mail server only allows mail to be sent using TLS over the submission port).

    Can anyone tell me how an alternate port is supposed to be defined?

    Thanks...
     
  2. tanstaafl

    tanstaafl Registered Member

    Joined:
    Apr 8, 2005
    Posts:
    207
    Anyone??
     
  3. DrewD

    DrewD Eset Staff Account

    Joined:
    Feb 19, 2010
    Posts:
    88
    You will not be able to append the port number to the end of the smtp server information, when using the client based notification

    You can use the ESET Remote Administrator Notification manager to receive email notifications of computers with threats.

    You first enter the SMTP information into the "OTHER SETTINGS" tab

    Tools > Server Options > Other Settings

    Here you can specify the port that you are wanting to use, as well as the rest of the SMTP server information.

    Next you want to setup a rule within ESET RA Notification Manager that will send you an email notification, when a computer has a threat.

    Tools > Notification Manager
     
  4. techie007

    techie007 Registered Member

    Joined:
    Jan 2, 2008
    Posts:
    125
    Location:
    Ontario, Canada
    Seeing as I gave up fighting with ESET about adding the custom email port well over a year ago (close to 2) -- half the Eset reps I spoke with said it works like that (i.e. you can use a custom port), the other half said it doesn't, but they plan on adding it (1-2 years later, and it's still not added).

    I've since been trying (on and off) to figure out HOW to do what you are proposing. The best I can figure out is how to get the RAS to notify me when there's an unclean threat after a scan.

    I want a notification each time a threat is discovered (cleaned, quarantined or otherwise) by the REAL-TIME scanners, not just a notification of uncleaned threats after an on-demand or scheduled scan.

    Is there a way to do this via the RA? If so, can you provide step-by-step info on HOW to set it up like that?

    It would be greatly appreciated. :)
     
  5. tony_m

    tony_m Eset Staff Account

    Joined:
    Nov 22, 2010
    Posts:
    239
    Hi techie007,

    Yes, it is possible to do so with ERA. First of all, as DrewD said, make sure your SMTP settings are correct (ERA Console >> Tools >> Server Options >> Other Settings).

    Now go to the Notification Manager (Tools >> Notification manager or Ctrl + T).

    Create a new rule and use the following parameters:

    Trigger type...
    New log event

    Parameters...
    Log type: Threat log
    Log level: level 2
    1 occurrences in 10 minutes
    Amount: >= 1 of filtered clients

    Action...
    Email to one address of your choice.

    Optional: Use "Log to file (server)" -> e.g. 'c:\notifications\log.txt' if you want to see when the rule is applied.

    We recommend to use the eicar file for your tests.

    Hope this helps.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.