---
title: "Configuring Notification Rules"
canonical: "https://docs.infoblox.com/space/nios85/35385553/Configuring%20Notification%20Rules"
format: markdown
---
You can configure notification rules after you have uploaded outbound templates and configured outbound endpoints on the NIOS appliance. For information about adding outbound endpoints, see <span style="color: #0000ff">[*Configuring Outbound Endpoints*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35752344)</span>. To send outbound notifications from NIOS to the target endpoints, you must configure notification rules. When adding rules, you can select REST API, DXL, or Syslog endpoint and associate the correct action template to the rule. The appliance validates the event type specified in the template with the event type that you select in the notification rule. The parameters defined in a template decides the way NIOS specific data is presented to an endpoint. Each notification rule specifies the target endpoint, notification rule criteria, and the outbound template being used to take action for the matching events.  

> ⚠️ **Note**
> ⚠️ 
> ⚠️ When you remove all the notification rules associated with an endpoint, all the debug logs for that endpoint will also be removed.


While configuring notification rules, you can decide whether you want to reduce the amount of redundant RPZ hits, ADP hits, and object change discovery data events. Oftentimes, these hits come from the same client IPs, query FQDNs, or networks. To avoid receiving excessive events at the endpoint, you can configure the appliance to remove or deduplicate subsequent events (after sending the first event) within a certain time period. Depending on your configuration, the appliance sends the first event and deduplicates subsequent events that match your filtering criteria within the configured lookback interval. For more information, see <span style="color: #0000ff">[*Deduplicating Events*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)</span>*.*

# > Macro (anchor)

> Macro (anchor)

Adding Notification Rules

To add notification rules:

1. From the **Grid/System** tab, select the **Ecosystem** tab -> **Notification** tab, and then click the Add icon.   
or  
From the **Grid/System **tab, select the **Ecosystem** tab, and click **Add** **Notification** **Rule** from the Toolbar.
2. In the *Add* *Notification* wizard, complete the following.
  - **Name**: Enter the name of the notification rule.
  - **Target**: Click **Select** **Endpoint** to select the endpoint type. If there are multiple endpoints, the *All* *Endpoints* *Selector* dialog box is displayed, from which you can select an endpoint name, such as **Cisco** **ISE**.
  - **Target** **Type**: Displays the target type. You cannot change this.
  - **Comment**: Enter useful information about the notification rule.
  - **Disable**: Select this option to disable the notification rule.
3. Click **Next** and complete the following to configure notification rules for the selected endpoint:
  - **Event**: Depending on the licenses you have installed in the Grid, you can select the event types you want to apply to the notification rules. The outbound member collects data for the selected events based on your configuration. Note that if there is a significant amount of data or if the network bandwidth is not sufficient, the outbound member might drop some of the events. In this case, you can access the syslog to view the messages related to dropped events. In addition to basic information (such as timestamp, member IP, network, and others), data collected for some event type might include enriched data such as discovered data, parent network information, and associated extensible attributes.

> ⚠️ **Notes**
> ⚠️ 
> ⚠️ - The event type you select here affects the templates that are available when you select the RESTful API template you want to use for the outbound notifications. For example, if you select **DNS****RPZ** as the event type, only templates configured for DNS RPZ event type are available for selection.
> ⚠️ - For the Cisco ISE endpoint, only the DNS RPZ, Security ADP, DHCP Leases, and ADP events are applicable.

From the drop-down list, select the event types you want to monitor for the notification rules:

> Macro (legacy-content)

In the **Match** **the** **following** **rule** section, select the filters, operators and values from the drop-down lists for the selected event type. You can use the + icon to construct nested expressions for the rule. The filters change depending on what you selected as the event type. Some of the filters are:

> Macro (legacy-content)

> ⚠️ **Notes**
> ⚠️ 
> ⚠️ An event may not be triggered and the template may not execute in the following scenarios:
> ⚠️ 
> ⚠️ - For events of type **Object Change DNS Record**:  
> ⚠️ - Microsoft synchronization of records, DDNS update of records, and nameserver update of records are not supported.  
> ⚠️ -  For SOA records, serial numbers are not automatically incremented.  
> ⚠️ -  For NS records, the **Comment** field is not updated.  
> ⚠️ -  For an RPZ rule, add and update operations are not supported.  
> ⚠️ - For a shared record, <span style="color: #333333">add and update operations are not supported.</span>  
> ⚠️ <span style="color: #333333">- For events of type </span>**<span style="color: #333333">Object Change DNS Zone</span>**<span style="color: #333333">, </span><span style="color: #333333">Microsoft </span><span style="color: #333333">synchronization </span><span style="color: #333333">of zones is not supported.</span>  
> ⚠️ <span style="color: #333333">- Transfer of secondary zones is not supported.</span>

4. Click **Next**. If you have selected **DNS** **RPZ**, or **Security ADP** or **Object Change Discovery Data** as the event type, go to *<span style="color: #0000ff">[Deduplicating](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)*<span style="color: #0000ff">[Events](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985) to configure deduplication. Otherwise, go to* *<span style="color: #0000ff">[*Selecting*](https://infoblox-docs.atlassian.net/wiki/display/nios83ga/Configuring+Notification+Rules#ConfiguringNotificationRules-bookmark3417)</span>[* *](https://infoblox-docs.atlassian.net/wiki/display/nios83ga/Configuring+Notification+Rules#ConfiguringNotificationRules-bookmark3417)<span style="color: #0000ff">[*Action*](https://infoblox-docs.atlassian.net/wiki/display/nios83ga/Configuring+Notification+Rules#ConfiguringNotificationRules-bookmark3417)</span>[* *](https://infoblox-docs.atlassian.net/wiki/display/nios83ga/Configuring+Notification+Rules#ConfiguringNotificationRules-bookmark3417)<span style="color: #0000ff">[*Template*](https://infoblox-docs.atlassian.net/wiki/display/nios83ga/Configuring+Notification+Rules#ConfiguringNotificationRules-bookmark3417)</span> to select an action template.

## Enabling Query FQDN for Outbound Notifications

Infoblox allows you to configure support for query FQDN for outbound threat protection events and choose maximum labels in FQDN that can be configured at the Grid and/or member level. When you enable query FQDN, event data will contain the `query_fqdn` field, if any, which is limited by the domain level. The outbound template executes the parameters and fields against the notification criteria to verify if the notification rule works for the selected security ADP event type.

Note that the maximum domain level is set to three and you can query for domain levels up to three. Example: If you set the domain level to two, you can query for domain a.com, but if you query a.b.com, then the outbound template does not execute the details against the notification criteria. When you set the domain level to three, you can query for a.b.com, but if you query for a.b.c.com, then the details are not executed. Query FQDN automatically prefixes a *. at the beginning of the domain name if the FQDN is longer.

You can enable query FQDN through the *Grid **Security Properties* or *Member Security Properties* editor. A warning message is displayed if the notification rule uses Query FQDN for filtering or deduplication when it is not enabled on each member.

To enable query FQDN for outbound notifications:

1. From the **Data Management** tab, select the **Security **tab, then click** Grid Security Properties** from the Toolbar.  
or  
From the **Data Management** tab, select the **Security **tab -> **Members** tab -> *member* checkbox, and then click the Edit icon.
2. In the *Grid Security Properties *or* Member Security Properties* editor, click **Toggle Advanced Mode**, select the **Ecosystem** tab, and complete the following:

> Macro (legacy-content)

# > Macro (anchor)

> Macro (anchor)

Deduplicating Events


> ⚠️ **Note**
> ⚠️ 
> ⚠️ This step appears only if you have selected **DNS** **RPZ**, or **Security ADP**, **Object Change Discovery Data**, or** DXL Events **as the event type.

Depending on your configuration, the appliance sends the first RPZ, or threat protection, or object change discovery data event and deduplicates subsequent events that match your filtering criteria within the specified lookback interval. The hits are considered based on the following fields for each of these event types:

- **RPZ events: **Source IP, Query Name, RPZ Policy, and other related fields.
- **ADP hits:** Source IP, Rule ID, and other corresponding fields.
- **Object Change Discovery Data**: Discoverer, IP Address, and other fields.

1. To avoid excessive notifications received at the endpoint, complete the following to configure event deduplication:
  - **Enable** **event** **deduplication**: Select this to enable event deduplication for RPZ, or ADP, or data discovery hits. When you enable deduplication, the appliance suppress redundant notifications based on your configuration.
  - **Log** **all** **dropped** **events** **due** **to** **deduplication** **to** **the** **syslog**: Select this if you want to log all the events that have been dropped due to deduplication. Selecting this allows the appliance to record all the dropped events to the syslog.
  - **Select** **the** **fields** **to** **use** **for** **deduplication**: From the **Available** table, pick the fields you want to use for filtering the deduplication and move them to the **Selected** table using the right arrow. You can also deselect any fields by selecting and moving them from the **Selected** table to the **Available** table using the left arrow. Event deduplication is done based on the conditions of the selected fields. The following example explains how deduplication works if two RPZ hits occur within the lookback interval, as follows:

`RPZ`` ``hit`` ``1 / ``ADP ``hit`` ``1`` / ``Data Discovery 1``: source_ip: 1.2.3.4, query_name: server1.bad.com, rpz_policy: NXDOMAIN, query_type: qname, network.network_view: internal, network.network: 1.2.3.0/24`  
` ``RPZ`` ``hit`` ``2`` /`` ADP hit`` ``2`` / `` Data Discovery 2``: source_ip: 1.2.3.4, query_name: www.something.com, rpz_policy: NXDOMAIN, query_type: qname, network.network_view: internal, network.network: 1.2.3.0/24`  
If you have selected only **Source** **IP** for deduplication, the appliance sends only the first RPZ event to the endpoint. If you have selected both **Source** **IP** and **Query** **Name**, both RPZ events are sent to the endpoint.

> Macro (legacy-content)

2. Click **Next** to select an action template for the endpoint, as described in *<span style="color: #0000ff">[Selecting](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)*<span style="color: #0000ff">[Action](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)*<span style="color: #0000ff">[Template](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)</span>*.

# > Macro (anchor)

> Macro (anchor)

Selecting Action Template

1. In this step, select the outbound template you want to use for outbound notifications. The appliance validates the event type that is added to the notification rule and then matches that with the event type configured in the template.
  In the **Template** field, click** Select Template** to associate an action template with the notification rule. If there are multiple templates, the <DXL or RESTful API> *Template Selector* dialog box is displayed, from which you can select an action template. Note that only templates that have the same event type configured for the notification rule appear in this dialog.
  The following information is displayed about the selected action template:

> Macro (legacy-content)

2. Save the endpoint configuration.

# > Macro (anchor)

> Macro (anchor)

Modifying Notification Rules

To modify a notification rule:

1. From the **Grid/System** tab, select the **Ecosystem** tab -> **Notification** tab, click the **Action** icon next to the notification rule and select **Edit** from the menu.
2. The *Notification* *Rule* editor provides the following tabs from which you can modify data:
  - **General**: You can modify the **Target** and **Comment** fields.
  - **Rules**: You can edit the event type and the rule, as described in *<span style="color: #0000ff">[Configuring](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)*<span style="color: #0000ff">[Notification](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)*<span style="color: #0000ff">[Rules](https://infoblox-docs.atlassian.net/wiki/spaces/nios85draft/pages/26478985)</span>*.
  - **Templates**: You can select a new action template for the notification rule.
3. Save the configuration.

# > Macro (anchor)

> Macro (anchor)

Viewing All Notification Rules

To view the list of notification rules:

1. From the **Grid/System** tab, select the **Ecosystem** tab, and click the **Notification** tab.
2. Grid Manager displays the following information:
  - **Name**: Name of the notification rule.
  - **Target**: The target name.
  - **Action**: The action type.
  - **Comment**: Comments that were entered for the notification rule.
  - **Disable**: Displays whether the notification rule is disabled.

You can do the following in this tab:

> Macro (legacy-content)

> ⚠️ **Note**
> ⚠️ 
> ⚠️ When you remove all the notification rules associated with an endpoint, all the debug logs for that endpoint will also be removed.

> Macro (legacy-content)

> Macro (legacy-content)

The appliance adds the quick filter to the quick filter drop-down list in the panel. Note that global filters are prefixed with [G], local filters with [L], and system filters with [S].

> Macro (legacy-content)