TZ 270 Sonic OS 7.x email events question.
We have been playing around with sending emails of important events. It seems to be somewhat useless at this point as we get thousands of emails and can find no way to reduce them.
We are looking to get only the absolutely critical "check the firewall NOW" types of emails. Not things that were attempted and defeated as they can be checked manually, and usually are every few days. We want to get and email when something is affecting the firewall that seriously is degrading performance or may be an actual breach. Getting tons of emails every day serves no purpose.
Anyway, I guess what I would like to know is how people use this feature and how they set it up.
Answers
Have a look at these two KB articles. I believe they should be able to help you.
https://www.sonicwall.com/support/knowledge-base/how-to-configure-log-automation-to-e-mail-log-categories-to-different-e-mail-addresses/170503263420646/
https://www.sonicwall.com/support/knowledge-base/sending-events-as-email-alerts/220512031719817/
Remove the email address from the alerts field under Device | Log | Automation, otherwise you will receive alerts for all events.