Skip to main content

Alerts

Alerts are automated notifications generated by Trisul's monitoring engine in response to predefined network activity, security anomalies, or system events.

Trisul allows administrators to set up alerts based on network activity, that enables real-time monitoring and notification of potential issues or security threats.

Alerts Viewing Options

Generated alerts can be accessed through two methods:

Alerts Bar

Alerts are displayed on the top right corner of the user home screen, updating automatically within a 1-minute interval.


Figure: Alerts and Notification Bar

Alerts Menu

Alerts can be analyzed in detail through the dedicated Alerts menu from the user home menu, providing a comprehensive view of network activity.


Figure: Alerts Menu

Alerts Notification Options

Trisul supports multiple notification channels for alert dispatch:

  • SYSLOG: Alerts can be forwarded to SYSLOG servers for centralized logging and analysis.
  • EMAIL: Alerts can be sent to designated email addresses, enabling prompt notification and response.
  • SMS: Alerts can be dispatched via SMS notifications, ensuring timely alerting and escalation.

The Email and SMS services work by reading the SYSLOG alerts. Ensure SYSLOG forwarding is enabled for each alert type.

Types of Alerts in Trisul

Trisul ships with 7 types of alerts.

Alert TypesDescription
Threshold Crossing AlertsAlerts triggered when a meter value (example: network traffic, bandwidth usage) exceeds fixed high or low watermarks for a specified time.
Flow Tracking AlertsAlerts generated when network flow behavior deviates from expected patterns.
Blacklist AlertsAlerts generated when blacklisted indicators (example: known malicious IP addresses, domains, or URLs) are detected.
IDS AlertsAlerts triggered when the system interfaces with external Intrusion Detection Systems (IDS) like Suricata.
Threshold Band Anomaly AlertsAlerts triggered when a meter value drifts outside a "trained" band of normal values.
System AlertsAlerts generated by Trisul's self-monitoring system, including Packet drops, Memory pressure.
User AlertsUser-defined alerts triggered to notify them of specific events or conditions that are important to them

This documentation covers a comprehensive guide on Trisul's alerting system including Alerts Classifications, Managing Alerts, Alerts Notification Channels and their Configuration.

Navigate the following topics in a sequential manner to facilitate a logical flow of information.