Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Alert Profiles

Want to summarize with AI?

Log in

Learn about using Alert Profiles in Multicloud Defense to define which events create alerts and where notifications are sent. Configure both alerts and services to support complete notification coverage.


Access the following Management views by navigating to System and Accounts > Service Alerts > Alert Rules.

Both the Services and Alerts page focus on alerts from Multicloud Defense. The Alerts page focuses on where alerts are sent to and the Alerts page details what alerts are sent to the endpoints configured. For ideal configuration, spend time setting up entries in both pages to successfully and wholly optimze the alert opportunity within the dashboard.


Services

Navigate to System and Accounts > Service Alerts > Services to view this page.

Services focuses on where you want to send alerts to. Note that you must provide criteria from the third-party application in order to successfully configure any options on this page.

Search

Use the search bar to seek or filter the list of services with key words. You must use at least three characters for the search to qualify.

Services Table and Actions

This table lists all the services that are created by Multicloud Defense components for your cloud service providers. View the name, type of service, the date the service was updated.

From here you can create or delete services. Note that these services are generated by Multicloud Defense and not related to the services your cloud service provider might provide.


Create a Service

Use the following procedure to create a service:

Before you begin

You must have service notifications or integrations enabled or allowed on your third party messaging application.

Procedure

1.

Navigate to System and Accounts > Service Alerts > Services.

2.

Click Create.

3.

Enter a unique Name.

4.

(Optional) Enter a Description. This may help differentiate between other services that may have a similar name.

5.

Use the drop-down menu to select the service Type:

  • Pager Duty.

  • ServiceNow.

  • Slack.

  • Datadog.

  • Microsoft Sentinel.

  • Microsoft Teams.

  • Webex.

  • Splunk.

6.

Depending on the service type, complete the following entries when prompted:

  • API Key.

  • API URL.

  • Azure Log Table Name.

  • Azure Log Analytics Workspace ID

  • (Optional for Splunk) Index.

7.

Click Save.


Edit a Service

Use the following procedure to edit an existing service:

Procedure

1.

Navigate to Navigate to System and Accounts > Service Alerts > Services.

2.

Locate and select the service within the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Edit.

4.

Modify the following aspects of the service:

  • Name.

  • Description.

  • Type.

  • Type-specific configuration criteria.

5.

Click Save to confirm the changes. At any point, click Cancel to close the window and cancel the changes.

What to do next

You may have to Refresh the page to see any changes.


Clone a Service

Use the following procedure to clone an existing service:

Procedure

1.

Navigate to System and Accounts > Service Alerts > Services.

2.

Locate and select the service within the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Clone.

4.

A clone of the service is generated. By default, only the service Type and any service-specific configuration criteria is retained.

5.

Enter a unique Name.

6.

(Optional) Enter a description.

7.

Click Save to confirm the changes. At any point, click Cancel to close the window and cancel the changes.

What to do next

You may have to Refresh the page to see changes or additions to the table.


Export a Service

Use the following procedure to export an existing service:

Procedure

1.

Navigate to System and Accounts > Service Alerts > Services.

2.

Locate and select the service within the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Export.

4.

Multicloud Defense generates an export wizard.

5.

Either click Download to download the terrform locally or click Copy Code to copy the JSON resource to manually paste into the terroform script.

6.

Within the terrform prompt, execute the command provided in the lower half of the window: terraform import "ciscomcd_alert_profile". "servicename" <number in table>

7.

Follow the prompts within terraform to complete the task. There are no more steps in the dashboard.


Delete a Service

Use the following procedure to delete an existing service:

Procedure

1.

Navigate to System and Accounts > Service Alerts > Services.

2.

Locate and select the service within the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Delete.

4.

Confirm you want to delete the service and click Yes.

5.

The service is removed from Multicloud Defense.


Alerts

The Alerts page focuses on what alerts are sent to the third-party endpoints.We strongly recommend configuring both alerts and services to take advantage of the alerts opportunity.


Create an Alert

Use the following procedure to create an alert:

Procedure

1.

Navigate to System and Accounts > Service Alerts > Alert Rules.

2.

Click Create.

3.

Enter a unique Name.

4.

(Optional) Enter a Description. This may help differentiate between other services that may have a similar name.

5.

Select the Alert Profile. At this time, Pagerduty is the only option available.

6.

Use the drop-down menu to select the alert Type.

  • System Logs.

  • Audit Logs.

  • Discovery.

7.

(Optional) Use the drop-down menu to select the Sub Type. Note that these options may change or may not be available depending on the Type you selected in step 6:

  • Gateway.

  • Account.

  • Controller.

  • Insights Rule.

8.

Use the drop-down menu and select the level of Severity:

  • Info.

  • Warning.

  • Medium.

  • High.

  • Critical.

9.

The Enabled checkbox is checked by default. This option designates whether the alert profile is active and usable or not. If it is disabled, Multicloud Defense does not include it when issuing alerts.

What to do next

Create a Service profile to designate where these alerts are sent to.


Edit an Alert

Use the following procedure to edit an existing alert:

Procedure

1.

Navigate to System and Accounts > Service Alerts > Alert Rules.

2.

Locate and select the alert within the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Edit.

4.

Edit any of the fields and selections of the alert proile. Note that some of the available fields may change depending on the selections you make.

5.

Click Save to confirm the changes. At any time, click Cancel to cancel the changes and close out the edit window.


Clone an Alert

Use the following procedure to clone an existing alert:

Procedure

1.

Navigate to System and Accounts > Service Alerts > Services.

2.

Locate and select the alert within the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Edit.

4.

A clone of the alert is generated. By default, only the Alert Profile and Type is retained.

5.

Edit any of the remaining fields and selections of the alert. Note that some of the available fields may change depending on the selections you make.

6.

Click Save to confirm the changes. At any time, click Cancel to cancel the changes and close out the edit window.


Export an Alert

Use the following procedure to export an existing alert:

Procedure

1.

Navigate to System and Accounts > Service Alerts > Alert Rules.

2.

Locate and select the alert within the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Export.

4.

Multicloud Defense generates an export wizard.

5.

Either click Download to download the terraform locally or click Copy Code to copy the JSON resource.

6.

Manually paste into the terraform script.

7.

Within the terraform prompt, execute the command provided in the lower half of the window: terraform import "ciscomcd_alert_rule"."alertname" <number in table>

8.

Follow the prompts within the terraform prompt to complete the task. Close the export window in Multicloud Defense. There are no more steps in the dashboard.


Delete an Alert

Use the following procedure to delete an existing alert:

Procedure

1.

Navigate to System and Accounts > Service Alerts > Alert Rules.

2.

Locate and select the alert within the table so it is highlighted.

3.

Expand the Actions drop-down menu and click Delete.

4.

Confirm you want to delete the service and click Yes.

5.

The alert is removed from Multicloud Defense.