Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Disable Mail Notification only for Third-Party Active Threat Response

Hello Sophos Community,

Recently, I added some IP blocklists to the new V21 Third-Party Threat Feed feature.
Some blocklists include a significant amount of content, which means it’s highly likely that flagged destination IP addresses will appear in the threat feed.
As a result, I’m now receiving a large number of email notifications indicating that a threat has been detected.

I would like to continue receiving email notifications for default Sophos Active Threat Response events (Sophos X-Ops & MDR), but notifications for Third-Party Threat Feed events are not necessary for me.
Is it possible to separate these notifications or manage them in a more granular way?

At the moment, it seems like everything is grouped together—MDR, Sophos X-Ops, and Third-Party Threat Feed

Does anyone have any ideas on how I can address this?

Thanks for your help!



Added TAGs
[edited by: Raphael Alganes at 11:11 AM (GMT -8) on 17 Jan 2025]
Parents Reply
  • We changed the behavior of WAN to LAN, to make ACLs hit first. So you could potentially create a ACL Exception Rule and block a lot of countries, which should not talk to you. This would reduce this kind of WAN to LAN Alerts. 
    The LAN to WAN Alerts are still there for now. 
    I am also talking about this situation here: v21 Third Party Feeds Because generally speaking, i am seeing a lot of customers using a lot of "data sources" which they do not know, how well maintain they are.  

    __________________________________________________________________________________________________________________

Children
No Data