Associated Events Email Notifications
Learn about the associated events in notification profiles.
| Where Can I Use This? | What Do I Need? |
|
|
- One of the following licenses:
|
Associate events are informational signals to get all updates related to an
incident excluding the initial trigger and resolution. To reduce unnecessary noise while
preserving visibility into incident lifecycle transitions (such as creation, update, and
resolution), Strata Cloud Manager suppresses associated event email notifications by
default for all notification profiles.
When configuring your notification preferences, you must distinguish between
the following event types:
Incident State Change events—Represent transitions in the
lifecycle of an incident (for example, when an incident is created, escalated,
or resolved). These events generate email notifications to drive independent
remediation or triage decisions.
Associated events—Indicate a new alert has been correlated with
an existing incident. While useful for tracking the scope of an incident, these
correlation updates are high-frequency and rarely require immediate action.
The
notification profile is the primary configuration object that
governs how and when you receive email notifications. Each notification profile includes
a preference that controls whether Associated events generate email notifications. This
preference is disabled by default for both existing and newly created profiles. When you
edit or create a notification profile, enabling this option resumes delivery of
Associated event emails for that specific profile, though the platform displays a
contextual message warning that enabling this setting might increase notification
volume.
If your security operations workflow depends on real-time awareness of every
alert associated with an active incident, you can enable Associated event email delivery
on the relevant notification profiles. If your team primarily acts on incident state
transitions and investigates correlated alerts through the web interface, leaving the
default suppressed behavior reduces inbox volume without affecting your ability to
manage incidents effectively. For Webhooks and ServiceNow, associated events continue to
be sent by default. You can disable it based on your requirements.