Configuring the Alert Queue

Use the Alert Queue tab to specify a maximum queue size and to specify how the Proventia Network IPS appliance acts if the queue is full.

About this task

Navigating in Proventia® Manager: Manage System Settings > Appliance > Alerts settings

Navigating in SiteProtector Management: select the Alerts policy

The appliance uses a queue file named SensorEventQueue.adf to store event alerts. Use the Alert Queue tab to determine how large this file can become before alerts are lost and how the queue file handles alerts after the maximum file size is reached.
Important: When you save changes on this page, the agent must restart. This may briefly impact your network and security, as the agent goes into bypass for a short time.

To retrieve Log Evidence files, Rolling Packet Capture files, and other log files, go to Review Analysis and Diagnostics > Downloads > Logs and Packet Captures.

Procedure
  1. Click the Alert Queue tab.
  2. Type a maximum size for the alert queue file.
  3. In the Proventia Manager alert queue full policy area, click one of the options:
    Option Description
    Stop Logging The queue file stops logging alerts when the maximum file size is reached.
    Wrap Around The queue file overwrites the oldest alert in order to create space for the new alert, when the maximum file size is reached.