Skip to main content

Alert Rules

Lacework combines alert channels and alert rules to provide a flexible method for routing alerts. For alert channels, you define information about where to send alerts, such as to Jira or Slack. For alert rules, you define information about which alert types to send, such as critical and high severity compliance alerts. This two-part method provides the flexibility to define multiple channels and multiple rules and then have each rule sent to the channels you specify.

You can define alert rules based on a combination of severity, resource group, and event category.

For example, you could define three channels in Lacework: email, Jira, and Slack. Then you can define multiple rules: critical severity alerts, high severity network and compliance alerts, medium alerts, and low and info alerts. Then select the appropriate channel(s) for each alert.

  1. Log in to the Lacework Console as a Lacework user with administrative privileges.

  2. Go to Settings > Notifications > Alert rules.

  3. Click + Add New.

  4. Name the rule and optionally provide a description.

  5. Select an alert channel for the rule to use. The list displays only enabled configured channels. Note that each alert rule can only have one bidirectional alert channel.

  6. Add additional channels if appropriate.

  7. Select the severities that you want the rule to apply to.

  8. Select the resource groups that you want the rule to apply to.
    The All AWS Accounts, All Tenants and Subscriptions, and All Organizations and Projects resource groups only apply to alerts related to the logging/config from the respective cloud provider (Config and CloudTrail events from AWS). The default cloud provider resource groups do not cover agent events from agents within the cloud providers. If you do not select any groups, the rule applies to all resource groups.

  9. Select the event categories that you want the rule to apply to.
    If you do not select any categories, the rule applies to all event categories.

  10. Click Save. The new rule appears in the table.

For example, you select the following: critical and high severities, Dev resource group, and compliance category. This results in critical and high severity compliance events in the Dev resource group using this alert rule through the alert channel that you specify.

Alert rules defined within an account can be used by that account only. They cannot be used by the organization. Alert rules defined at the organization level can be used at the organization level only. They cannot be used by accounts.