Add Notifications
A notification is a link between a template, an endpoint, and an event. In the notification you define the event which triggers the notification, executed template, and the API endpoint of which the Grid will establish a connection. To simplify deployment, create only required notifications and use relevant filters. It is highly recommended to configure deduplication for RPZ events and exclude a feed automatically populated by Threat Analytics. NOTE: when using Test Rule, rules for that notification apply.
An endpoint and a template must be added before you can add a notification. Let’s add a notification.
Navigate to Grid → Ecosystem → Notification. Click Add
Notification Rule in the Toolbar or the Add
button.
Enter a Name and select the Target Endpoint. You cannot change the name later. Click Next.
Select the Event and define rules that will trigger the Outbound API template to execute. Rules act as a filter in which only when they are satisfied will the template execute. You can choose to match all rules or any of multiple. Click Next. NOTE: For optimal performance, it is best practice to make the rule filter as narrow as possible.
Select Enable event deduplication if desired and applicable. Click Next.
Select the desired/applicable template to execute. Click Save & Close.