tencent cloud

All product documents
Cloud Workload Protection Platform
Alarm Setting
Last updated: 2025-04-10 16:55:19
Alarm Setting
Last updated: 2025-04-10 16:55:19
this document aims to guide users How to configure alarms so that they can timely acquire messages such as CWP alarms, log capacity warnings, client running conditions, and security broadcasts.

Alert Catalog

The current alarm rule configuration supports two methods: Message Center/Short Message Service/Email and robot notification. The former needs to be used in conjunction with Message Center.
Major Category of Alarm
Alarm Type
Alarm Item
Alert Range
Message Center/SMS/Mail, Etc
Robot Notification
Alarm Time
Alarm Time
Intrusion detection
Virus scanning
Serious, High risk, Medium risk, Low risk, Note.
All/Custom
All-day/Custom
Note:
To reduce disturbance to users, Alarms have the following restrictions:
At the start of the alarm time period, receive real-time notifications for the first 3 security alarms, followed by a summary notification every 2 hours.
Alarms generated during the non-alarm time period will be summarized and notified at the start of the alarm time.
real-time
Virus Scanning - abnormal process
An abnormal process running in memory has been detected.
Unusual login
High risk, Suspicious.
Password cracking
The login password has been successfully cracked.
Malicious request
The server requested a malicious domain name.
High-risk command
High risk, Medium risk, Low risk.
Local privilege escalation
Low privilege attempting to elevate in the system.
Reverse Shell
A Shell reverse connection occurs on servers.
Vulnerability management
Urgent vulnerability
Serious, High risk, Medium risk, Low risk.
Linux software vulnerability
Serious, High risk, Medium risk, Low risk.
Windows system vulnerability
Serious, High risk, Medium risk, Low risk.
Web-CMS vulnerability
Serious, High risk, Medium risk, Low risk.
Application vulnerability
Serious, High risk, Medium risk, Low risk.
Vulnerability defense
Successfully defended vulnerability exploitation attack event.
Baseline management
Security Baseline
Exist baseline items that fail detection (account-related, weak password, unauthorized access baselines).
Cyber Defense
Network attack
Successful attack, attempted attack.
Java Webshell
A Java Webshell has been detected in the JavaWeb Service Process.
Core file monitoring
High risk, Medium risk, Low risk, None.
Client-related
Client offline
Client abnormal offline has been detected and it has not been back online within a specified period.
Client uninstallation
Client uninstalled has been detected.
Log Analysis
Log analysis storage
When the log storage volume reaches a certain percentage, a log storage alarm will be triggered.
Not involved
real-time
News-related
Security Broadcast
Security announcement Version release Feature updates Practice Industry honor

Message Center/SMS/Mail, Etc

1. Before configuring alarm rules, first ensure that the do not disturb switch for CWP in Message Center > Subscription Management is turned off, and set the receiving channel and recipient.
Receiving channels: CWPP supports receiving through Message Center, mail, SMS, WeChat, and WeCom. Voice reception is not supported (not effective when checked).
Message recipient: Support users, user groups, IM applications, robots.



2. In the CWP console Settings Center > Alarm Setting, select Message Center/SMS/Mail, Etc to configure alarm rules just.




Robot Notification

Messages can be sent to IM groups via robots as message recipients. The above method also supports robot notifications, but only based on the configured alarm rules of Message Center/SMS/Mail, Etc. If you wish to configure different alarm rules for different robots, this approach can be adopted.
Note:
Before configuring robot notifications, create a group bot in the IM group (such as a WeCom group) and obtain its Webhook address. For details, see Creation Guide for WeCom Chatbot.
1. Log in to CWP Console. In the left sidebar, select Settings Center > Alarm Settings.
2. On the alarm settings page, select Robot Notification > Receive Bot Management.



1. Click Create Robot, fill in the bot name and Webhook address, and click Save.



2. Select Alarm Policy Configuration, click Create Alarm Policies, configure the Policy Name, Enable Status, Alarm Range, etc., and associate with the receiving robot just created.



3. Click Save. Subsequently, CWPP will send message notifications according to your configuration.



Was this page helpful?
You can also Contact Sales or Submit a Ticket for help.
Yes
No

Feedback

Contact Us

Contact our sales team or business advisors to help your business.

Technical Support

Open a ticket if you're looking for further assistance. Our Ticket is 7x24 available.

7x24 Phone Support
Hong Kong, China
+852 800 906 020 (Toll Free)
United States
+1 844 606 0804 (Toll Free)
United Kingdom
+44 808 196 4551 (Toll Free)
Canada
+1 888 605 7930 (Toll Free)
Australia
+61 1300 986 386 (Toll Free)
EdgeOne hotline
+852 300 80699
More local hotlines coming soon