Skip to content

Integration health alerts

When a data ingestion integration is offline or unhealthy, Sophos Fusion generates an alert. By default, Sophos Fusion also sends an email notification to all Sophos Fusion administrators for that alert.

This page tells you how the Sophos Fusion alerts work and how to customize email notifications.

How the Sophos Fusion alerts work

Sophos Fusion generates a medium-severity alert when an integration remains offline or in a "failed" status for 24 hours.

The 24-hour period begins when Sophos Fusion receives the first failure message. An alert is sent only if the failure continues throughout that period.

The 24-hour countdown to an alert resets when one of the following changes happens:

  • The integration health status changes to green.
  • An administrator acknowledges the alert.

If the issue persists, the alert reappears once every 30 days.

Change the frequency of email alerts

If you've received an integration health alert in Sophos Fusion, you can change how often Sophos Fusion sends email notifications about that alert to administrators.

  1. Go to My Environment > Alerts.

    My Environment > Alerts.

  2. Click the integration health alert to see its details.

    Sophos Fusion alerts page with alert details open.

  3. On the right of the page, under Email alert, select the frequency.

    Email alerts frequency options.

Specify which administrators receive email alerts

You can specify which administrators receive email notifications about integration health alerts. To do this, you must set a custom rule.

Warning

Setting a custom rule turns off the default sending of all email notifications to all administrators. If you want to continue sending some email notifications to all administrators, you'll need to set that up in another custom rule.

To set a custom rule, do as follows:

  1. Click the General Settings icon .
  2. Under General, click Configure email alerts.

    "Configure email alerts" in the General section.

  3. On the Configure email alerts page, select the Custom rules tab.

    "Configure email alerts" page.

  4. On the Custom rules tab, click Create rule.

    "Custom rules" tab with the "Create rule" button.

  5. On the Create Notification Rule page, the Role section is open by default. Select the administrator role to which the rule will apply, then click Next.

    Select role.

  6. In Administrators & Distribution lists, all administrators with the required role are shown. Select the administrators who will receive email notifications, then click Next.

  7. In Devices, turn email notifications on or off for all computers and all servers, and click Next.
  8. In Alert Types, turn on email notifications about alert types that match integration health alerts, as follows:

    1. In Set by severity, select Medium alert. All integration health alerts have this severity.
    2. In Set by product, leave Sophos Central selected. Deselect other options unless you want the same administrators to receive email notifications about other non-integration alerts.
    3. In Set by category, leave Central Integrations Alert selected. Deselect other options, unless you want the same administrators to receive email notifications about other, non-integrations alerts.
    4. Click Next.

    Alert types section, with the Set by severity options shown.

  9. In Name and Description, name the rule and add a description.

  10. Click Save.
  11. The new rule is shown on the Custom rules tab.

    New rule listed in Custom rules.