Alerting Issue in UI in RSA Web Threat Detection 5.1.0.7 Custom Key
Originally Published: 2016-09-08
Last Modified: 2023-12-01
Article Number
Applies To
RSA Product/Service Type: Mitigator
RSA Version/Condition: 5.1, 5.2,6.0
Issue
When setting up a custom key and using that key as the Alert Key in a rule, the system does not flag the alert in the UI. We have tested alerting to email, and the email arrives (telling us that the alert triggered), but there is still no alert visible in the UI. Thus, this appears to be a UI-only issue, where alerts triggered against custom keys do not appear.
As stated above, this rule sends out emails when it alerts, proving that it indeed triggers as expected, but the alert never shows in the UI.
Resolution
"Alerts listing and the Current Real Time Alerts list will only show alerts keyed against "ip, page, and user". By default there are 8 total keys to select from in the rule creation page under the "Alert Key" drop down list."
This is now fixed in version WTD 6.1 that is scheduled to be released in October 2016.
What was fixed --
"Remove filtering on javascript code that filters all keys except for ip, user and page.
All keys are now supported."
Tested the fix --
"creating a RT rule and setting alert keys as : user_ip & user_page & ip_page & agent
when rule is triggered, all keys displayed in the alerts section"
Related Articles
RSA Authentication Manager 8.1 Performance and Scalability Guide 10Number of Views Restore database script does not load the data 36Number of Views Configuration options for RADIUS Client load balancing with Authentication Manager 8.6 184Number of Views RSA Authentication Agent 8.6 API does not prompt for passcode with Epic Hyperspace 2016 on Windows Server 151Number of Views RSA Authentication Agent 7.4 for Microsoft Windows Installation and Administration Guide (French) 39Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x
Don't see what you're looking for?