Updated on 2024-04-11 GMT+08:00

Overview

Scenario

SecMaster provides this playbook for real-time notification of key O&M operations. Based on O&M operations, SecMaster notifies you of key O&M operations by email in real time.

How the Playbook Works

The Real-time notification of critical Organization and Management operations playbook has matched the Real-time notification of critical Organization and Management operations workflow. This workflow uses Simple Message Notification (SMN) to send notifications. So you need to create and subscribe to a notification topic in SMN.

Figure 1 Real-time notification of critical Organization and Management operations workflow

Prerequisites

  • You have enabled CTS logs on the Data Integration page under Settings in the current workspace. For details, see Data Integration.
    Figure 2 Access to CTS logs
  • The corresponding O&M defense model has been enabled. For details, see Enabling an Alert Model.

Verification

When a key O&M operation is performed, this playbook is triggered. The playbook will send an email notification as configured. The following is an example.

Figure 3 Operation notifications