Configure custom alert policies for security events, newly discovered public-facing assets, unprotected assets, and storage capacity overages. Multiple notification channels are available, including email and site messages, so you can identify and respond to security risks in a timely manner.
Procedure
Step 1: Configure notification recipients
Before configuring notification items, specify who will receive notifications. By default, the recipient is the account contact specified during registration.
-
Log on to the Message Center. In the left-side navigation pane, choose Common Settings.
-
On the Security Message tab, locate Cloud Shield Security Notification and click Modify in the Actions column to go to the Modify Message Receiving Configurations page.
-
On the Contact tab, manage notification recipients.
-
Select existing contacts: In the dialog box that appears, select the contacts you want to receive notifications.
-
Add a new contact: To add a new contact, see Managecontacts.
-
-
After making your selections, click Save.
To configure contact email receiving rules and notification language, see the Message Center settings. For detailed steps, see Manage notification settings.
Step 2: Configure notifications
-
Sign in to the Agentic NDR Console.
-
In the left-side navigation pane, choose .
-
Locate the target notification item and configure the notification policy:
-
Notification Time: Set the time period during which alert notifications are sent.
-
Level / Threshold: Set the conditions that trigger notifications. For Security Event Notification, configure the event severity levels to monitor. For Log Storage Capacity Overage Notification and Packet Storage Capacity Overage Notification, configure the usage threshold percentage that triggers alerts.
-
Notification Method: Select the channel for receiving alert notifications.
-
Disable notifications
If you no longer need NDR security notifications, disable them as follows.
-
Sign in to the Agentic NDR Console.
-
In the left-side navigation pane, choose .
-
Locate the target Notification Item and clear all channels in its Notification Method column.
FAQ
Why am I not receiving notifications after configuring them?
Troubleshoot as follows:
-
Check recipients: Verify that contact information has been added and confirmed.
-
Check notification configuration: Verify that the relevant notification item has at least one notification method enabled and that the settings (such as severity level and threshold percentage) match the actual triggering conditions.
-
Check spam folder: Check your email spam folder.
-
Check rate limiting: See the Notification frequency and rate limiting rules section to check whether you have reached the daily sending limit.
-
Check deduplication: Each security event triggers only one notification. Notifications are not resent if the event persists or its severity level escalates.
Are notifications enabled by default after activating NDR?
Yes. When a new user activates an NDR instance, default configurations are applied to all notification items automatically. You can modify these settings in the console at any time.
How can I prevent a specific contact from receiving NDR notifications?
Set custom email receiving rules for a specific contact and use blocklist keywords to filter out NDR-related notifications:
-
Log on to the Message Center. In the left-side navigation pane, choose Common Settings.
-
On the Security Message tab, locate Cloud Shield Security Notification and click Modify in the Actions column to go to the Modify Message Receiving Configurations page.
-
Locate the target contact, click Edit in the Receiving Rules column, select Blacklist Keywords, enter NDR and click OK.
After this setting is applied, the contact no longer receives SMS or email notifications containing the keyword "NDR". Other contacts are not affected. For more information, see Configure message receiving.
Appendix
Notification frequency and rate limiting rules
To prevent notification overload, NDR applies deduplication and rate limiting for different notification types:
|
Notification Item |
Deduplication Rules |
Daily Rate Limiting Rules |
|
Security Event Notification |
Each event is notified only once. |
A maximum of 20 notifications per day. |
|
New Public Assets Notification |
Each user can trigger at most one notification per hour. |
A maximum of 5 notifications per day. |
|
Asset Unprotected Notification |
Each user can trigger at most one notification per day. |
A maximum of 1 notification per day. |
|
Log Storage Capacity Overage Notification |
Each user can trigger at most one notification per day. |
A maximum of 5 notifications per day. |
|
Packet Storage Capacity Overage Notification |
Each user can trigger at most one notification per day. |
A maximum of 5 notifications per day. |
Supported notification content
-
Security Event Notification: When NDR detects an attack event (such as brute-force attacks, lateral movement, or C&C communication), alerts are sent in real time based on the configured severity levels. The notification includes key information such as the event name, severity level, attacker IP and location, attack type, and the number of associated alerts. If an AI analysis report is available, the notification also includes an analysis summary and remediation recommendations.
-
New Public Assets Notification: When NDR discovers a new public-facing asset, a real-time notification is sent, prompting you to enable the Automatic Protection for New Assets feature to reduce manual configuration overhead.
-
Asset Unprotected Notification: NDR regularly compiles a weekly summary of public IPs and private network assets without NDR protection and sends a weekly reminder to enable protection.
-
Log Storage Capacity Overage Notification: Triggered when log analysis storage usage reaches the configured threshold. If the capacity limit is exceeded, log writing stops. Expand the storage capacity promptly.
-
Packet Storage Capacity Overage Notification: Triggered when packet retention storage usage reaches the configured threshold. If the capacity limit is exceeded, the oldest packets are automatically deleted to free up space. Expand the storage capacity promptly to avoid losing historical data.