Configure Email Alerts

You can set up email alerts for threats, system status, and configurations to stay updated on important changes. Once you configure these alerts, Qualys automatically sends daily email notifications for any new asset activity that requires your urgent attention, helping you respond quickly in a rapidly changing environment.

You will receive email notifications only for the new asset notifications daily, reducing unnecessary emails and duplication.

Email Alerts can be accessed under the Notifications menu. To configure email alerts, click Notifications.

Here is an example of an email alert:

Email Alerts Categories

You can enable alerts for the following categories:

Threat Alerts: Notifications related to potential or identified threats, enabling users to take proactive measures.

Active Threat Alerts: Alerts for threats with a high-risk score, providing better visibility into malicious activities and enabling a quick response to such threats.

  • Trigger conditions: You receive the email threat alert when the high-risk events score reaches 4 or more than 4.
  • Frequency: A maximum of five email alerts are sent with a four-hour cooling period that starts before new alerts are triggered.
  • Email details: Each email includes a list of threat events along with detection time, severity score, and a direct link to view each event.

Here is an example of the Active Threat Alert Email:

Once you select the View Event option, you are directed to the event details page, where you can quarantine or delete the event, or you can kill the process itself.

To view more events, click View More Events, and you are redirected to the Hunting tab, where you can take action against the threat event.

System Status Alerts: Updates on the health and performance of the system, helping users monitor uptime and resolve issues promptly.

Configuration Alerts: Alerts about configuration changes or inconsistencies to ensure that system settings remain optimal and secure.

How to Configure Alerts

There are two ways of configuring email alerts. You can enable all notifications or only those you want to be notified. 

To configure all alerts Click Enable all toggle > click Yes to confirm, and then click Save
To configure individual alerts Select the toggles for the alerts you want to receive and then click Save.
To reset the configuration

Click Reset and then click Save. The configurations will be reset to the default configuration.

To disable all alerts

Click Enable all toggle > click Yes to confirm, and then click Save.

All email alerts will be turned off immediately.

Configure Trigger Criteria for Email Alerts

You can control how and when you receive email notifications for EDR alerts by choosing from three trigger criteria:

  • Single Match
  • Time-Window Count Match, or
  • Time-Window Scheduled Match

This lets you align alert frequency with your team's monitoring workflow instead of receiving a separate email for every event.

Each trigger criteria type determines when the notification job evaluates matching events and sends an email:

  • Single Match: Sends one email for each individual matching event. You can cap the number of emails using a Max Email Limit and an Email Cooling Period (hours). Once the limit is reached, no further emails are sent until the cooling period elapses.
  • Time-Window Count Match: Sends a single email once a configured number of matching events occurs within a configured time window. For example, you can trigger an email only when 5 matching events occur within a 15-minute window.
  • Time-Window Scheduled Match: Sends notifications on a recurring Daily, Weekly, or Monthly schedule instead of in near real time. For example, you can receive one email that lists all matches collected during a scheduled window.

Trigger criteria is configured on the Configure Notification option for each alert type. To view the trigger criteria, go to Notifications page, click the more options icon () for the alert card you want to configure, and click Configure Notification.

The Configure Notification window displays the alert Type and a Trigger Criteria list with the three options described above.

Trigger Criteria Options

Depending on the trigger criteria you select, the dialog displays the fields described below.

Trigger Criteria Fields Description
Single Match Max Email Limit The maximum number of emails to send for the alert before the cooling period starts.
Email Cooling Period (hours) The number of hours to wait, after the Max Email Limit is reached, before sending further email alerts.
Time-Window Count Match No. Of Matching Events The number of matching events required, within the configured time window, to trigger an email.
In / Unit The length of the time window (in Minutes, Hours, or Days) in which the matching events must occur.
Aggregate Value Set to Yes to group multiple matching events into a single email, or No to send events individually within the time window.
Aggregate Group Available when Aggregate Value is set to Yes. Select Malware Family, Hash, or Severity to group matching events in the email by that field.
Time-Window Scheduled Match Repeats Select Daily, Weekly, or Monthly to define how often the notification job runs and sends an email.
Aggregate Group Select Malware Family, Hash, or Severity to group the matching events collected during the scheduled window into a single email.
Send emails only for new events Select this checkbox to skip sending an email for a scheduled run when no new events have been detected since the last scheduled email.

To configure trigger criteria for an alert:

  1. Go to Notifications page, click the click the more options icon () on the alert card you want to configure, and select Configure Notification.
  2. From the Trigger Criteria list, select Single Match, Time-Window Count Match, or Time-Window Scheduled Match.
  3. Specify the fields for the selected trigger criteria, as described in Trigger Criteria Options.
  4. Click Save.

Here is an example of the Time-Window Count Match criteria configured to trigger an email when 5 matching events occur within a 15-minute window, with aggregation enabled, aggregation group set to Severity.

Here is an example of the Time-Window Scheduled Match criteria configured to send an email every month, with events grouped by Aggregate Group and repeat emails skipped when there are no new events:

Note:

  • Aggregation (grouping matching events by Malware Family, Hash, or Severity) is available only for the Active Threat Alert and Threat Neutralization Alert, and only when using Time-Window Count Match or Time-Window Scheduled Match. For Time-Window Count Match, aggregation is turned on using the Aggregate Value field. For Time-Window Scheduled Match, aggregation is turned on by selecting a field directly in the Aggregate Group list.
  • Not all trigger criteria are available for every alert type. Alerts that are based on time-based queries such as Overdue Anti-Malware Scan Alert, Device Disconnect Alert, and Outdated Virus Definitions Alert, support only Time-Window Scheduled Match, since these alerts are evaluated against conditions measured over an extended period, such as a scan not having run in 7 days.

How to Manage Email Alerts

To manage the email alerts, perform the following steps:

  1. Click Manage Email Settings on the Notifications page.

  2. Specify email addresses to receive the alerts.

  3. Click Save.