Configuring External alerts with alert responses
An alert response is a configuration that defines a connection to external servers or services, such as email servers, Simple Network Management Protocol (SNMP) servers, syslog servers, or webhook endpoints. Alert response in Firewall Management Center enables you to send notifications about security events from Firewall Management Center to external monitoring servers or designated recipients. These configurations are called “responses” because they send alerts in response to events detected by the Firewall Threat Defense device.
To send external alerts from Firewall Management Center:
-
Create alert responses for supported protocols (SNMP, syslog, email, webhooks). Specify required parameters such as server addresses, ports, credentials, and message formats.
-
Assign alert responses to specific alert types or event categories to send alerts based on event characteristics.
You can configure multiple alert responses to send different types of alerts to different monitoring servers or personnel (recipients).
Firewall Management Center sends alerts to the external systems using alert responses. By contrast, SNMP and syslog alerts triggered by individual intrusion rules are sent directly by the managed devices. For more information, see External Alerting for Intrusion Events. Firewall Management Center also sends intrusion email alerts, which do not use alert responses.
External alert types
After you create an alert response, you can use it to send the following external alerts from the Firewall Management Center.
|
Event and alert type |
For more information, refer to |
|---|---|
|
Health events, by health module and severity level |



Feedback