How to create an alert/email notification when NTA server is down?

Hello everyone,

do you have any idea how to create some sort of alerting whenever the NTA server is physically down? by creating a custom alert or some kind of notification signaling…
Any idea is more than welcomed.

Thank you in advance!

Hi Dejan,

yes you can create an Inactivity Alert.

The steps to create this are, navigate to log search.

Select the Network Flow Logset
Screen Shot 2021-04-22 at 12.28.30 PM

Select Add Alert → Inactivity Detection Alert
Screen Shot 2021-04-22 at 12.28.36 PM

Then configure the Trigger Setting as required (10 minutes minimum)
Screen Shot 2021-04-22 at 12.30.30 PM

If you have multiple network sensors, if any of the sensors stop sending data for 10 minutes (adjust accordingly) or more and then the alert will fire.

You can choose to Create an Investigation, or alternatively you can choose to send it to an Email, Slack, Pagerduty or Webhook, or even an ICON workflow.



Thanks David!

hey @david_smith as a follow-up question, how can we know when the sensor is up again without going into the portal? Can we create some form of (email) notification as well?