Hello Sophos Community,
Recently, I added some IP blocklists to the new V21 Third-Party Threat Feed feature.
Some blocklists include a significant amount of content, which means it’s highly likely that flagged destination IP addresses will appear in the threat feed.
As a result, I’m now receiving a large number of email notifications indicating that a threat has been detected.
I would like to continue receiving email notifications for default Sophos Active Threat Response events (Sophos X-Ops & MDR), but notifications for Third-Party Threat Feed events are not necessary for me.
Is it possible to separate these notifications or manage them in a more granular way?
At the moment, it seems like everything is grouped together—MDR, Sophos X-Ops, and Third-Party Threat Feed
Does anyone have any ideas on how I can address this?
Thanks for your help!
Added TAGs
[edited by: Raphael Alganes at 11:11 AM (GMT -8) on 17 Jan 2025]