If you create a firewall rule that blocks and alerts, any time that rule is triggered, an alert displays on the Alerts page.

Procedure

  1. In the left navigation pane, click Alerts.
  2. Set the filter to Host-based Firewall.
  3. View any detected alerts that were triggered by a Host-based Firewall rule. For example:
    Image of example alerts
    Note:
    • To reduce noise on the Investigate and Alert Triage pages, Carbon Black can limit the number of events associated with an alert that a specific Host-based Firewall rule generates. This limit is never less than 100 events.
    • The severity of the alert is determined based on the value provided when creating the rule. For further information, see Add a Host-based Firewall Rule Group.
  4. Double-click an alert or click the right arrow Right arrow to expand to expand the Alert Details pane. The Alert Details pane provides further information about the Host-based Firewall rule that triggered the alert, including the number of times the behavior was observed. You can directly navigate to the rule and policy for any necessary rule parameter changes or review.