Querying Audit Records : Setting an Action for an Alert

Setting an Action for an Alert
Once you have added an alert, you need to set an action to be performed each time AuditMaster finds a match for the alert condition.
You can set one or both of two actions for each alert:
n
n
Note From a viewer client on the server machine where AuditMaster is running, you can set actions both to send email or run a program on the server; however, from a remote viewer client you are unable to set an action to run a program on the server and can set only email alerts.
1
Select File Alerts if the Alerts window is not open, and select an alert to configure.
2
Click Edit.
The Action for Alert window appears.
3
w
EmailAlert
The EmailAlert action sends an email to a specified group of addresses when an alert condition is met. To configure the email alert action, proceed to Setting an EmailAlert Action.
w
RunProgram
The RunProgram action runs a specified program on the server when an alert condition is met. To configure the program, proceed to Setting a RunProgram Action.
4
Selected actions are now set for the alert and will be performed if the alert condition is met.
Note After creating or changing an alert, close AuditMaster Viewer and restart the AuditMaster event handler so that the alert takes effect. See Restarting the AuditMaster Event Handler.
Setting an EmailAlert Action
1
If the Alerts window is not open, select File Alerts, select the alert to configure, click the Action button, click EmailAlert, and click the Select button.
The EmailAlert action moves to the Selected Actions column.
2
The Configure EmailAlert window appears.
3
When the alert condition is met, addresses in this group will receive email.
4
5
For example, if your out-going mail server is named smtp-server.companyname.com, then enter smtp-server in this field.
6
7
Add the domain name, such as pervasive.com, and click OK. Continuing with the example from the last step, here you would enter companyname.com.
8
The Configure Groups window appears. For this demonstration, sample values have been filled in.
9
 
Click Add New Group, enter a name for the new group, and click OK.
Select a group name, click Edit Group Name, enter a new name for this group, and click OK.
Select a group name, click Delete Group, and click Yes to confirm. The group is deleted only for this alert and remains in the system for use in other alerts.
With a group selected, click Add New E-mail Address, enter the email address, and click OK.
With a group selected, select an email address, click Remove E-mail Address, and click Yes to confirm.
The following sample email alert was tripped by an insert in the Demodata database. If AuditMaster monitors a database without a schema, the application record data in the alert does not display the hexadecimal content. If the schema has been imported, then column names are displayed.
Figure 7-5 Structure of an Email Alert
Setting a RunProgram Action
1
If the Alerts window is not open, select File Alerts, select the alert to configure, click the Action button, click RunProgram, and click the Select button.
The RunProgram action moves to the Selected Actions column.
2
The Configure Programs window appears.
3
 
1.
Click the Add button.
2.
Click Remove.
3.
Click Yes to confirm.
2.
Click Set Parameters.
3.
Click the buttons to Add, Remove, or Change parameters for the program to be run.
4
5
Click Close to exit from the Alerts window.
Editing an Existing Alert
You can edit the name and description of an alert. However, you cannot change the conditions for the alert. To monitor for a different event, delete the old alert and enter a new one.
1
The Edit Alert window appears.
Figure 7-6 Edit Alert Window
2