Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Disable Mail Notification only for Third-Party Active Threat Response

Hello Sophos Community,

Recently, I added some IP blocklists to the new V21 Third-Party Threat Feed feature.
Some blocklists include a significant amount of content, which means it’s highly likely that flagged destination IP addresses will appear in the threat feed.
As a result, I’m now receiving a large number of email notifications indicating that a threat has been detected.

I would like to continue receiving email notifications for default Sophos Active Threat Response events (Sophos X-Ops & MDR), but notifications for Third-Party Threat Feed events are not necessary for me.
Is it possible to separate these notifications or manage them in a more granular way?

At the moment, it seems like everything is grouped together—MDR, Sophos X-Ops, and Third-Party Threat Feed

Does anyone have any ideas on how I can address this?

Thanks for your help!



Added TAGs
[edited by: Raphael Alganes at 11:11 AM (GMT -8) on 17 Jan 2025]
Parents
  • We have this on our radar, as this came up in the EAP as well. 

    Basically all systems use the ATP to generate and do something. We are looking into changing this behavior, which is not that easy in ATP itself. 

    Do you get those notifications from LAN to WAN Traffic, or WAN to LAN? 

    __________________________________________________________________________________________________________________

Reply
  • We have this on our radar, as this came up in the EAP as well. 

    Basically all systems use the ATP to generate and do something. We are looking into changing this behavior, which is not that easy in ATP itself. 

    Do you get those notifications from LAN to WAN Traffic, or WAN to LAN? 

    __________________________________________________________________________________________________________________

Children