Jump to content


cylonsurfer

Question about SCCM CB Alerts

Recommended Posts

I have configured a number of Malware alerts in SCCM CB and have tested them against a test client which I infected with the EICar test file. The configured alerts all trigger as expected and fire off emails to the addresses I have specified - which is great. However once triggered these alerts seem to remain in a state of 'Active' under 'Monitoring' > 'Overveiw' > 'Alerts' > 'All Alerts' / 'Active Alerts' despite the malware being successfully removed from the client via Endpoint Protection and the client reporting a remediation status of 'Cleaned' back to SCCM.

I can see no way to dismiss these alerts or manually mark them as resolved - what do I do with them and should they automatically change state once the issue that triggered them has been resolved? It's been over 48 hours since the Malware was detected (and removed) by Endpoint and the alert triggered in SCCM.

Edited by cylonsurfer

Share this post


Link to post
Share on other sites

Thats correct - the alerts, once triggered remain active even although the malware which triggered the alert was cleaned and I can see no way to manually dismiss the alerts and they do not appear to be resolving automatically.

We're currently on version: 1706 - Site Version: 5.00.8540.1000

Share this post


Link to post
Share on other sites

according to this link the following actions are available for alerts

Quote

 

You can take one of the following actions when Configuration Manager generates an alert:

Resolve the condition that caused the alert, for example, you resolve a network issue or a configuration issue that generated the alert. After Configuration Manager detects that the issue no longer exists, the alert state changes to Cancel.

If the alert is a known issue, you can postpone the alert for a specific length of time. At that time, Configuration Manager updates the alert to its current state.

You can postpone an alert only when it is active.

You can edit the Comment of an alert so that other administrative users can see that you are aware of the alert. For example, in the comment you can identify how to resolve the condition, provide information about the current status of the condition, or explain why you postponed the alert.

 

So have your alerts state changed to cancel ? can you show a screenshot ?

cheers

niall

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.