The Alerts and Alert Configurations features are RBAC-enabled. To configure alerts and webhooks you need to set the permissions to view or manage to use these features.
The New Alert Configuration window gives you the ability to configure eight types of alerts.
The following provides you with information about the fields in the “New Alert Configuration” window:
- Alert Name: Enter the name of your new alert configuration in this field.
- Status: Set the status toggle to determine the status of a new alert:
- Enabled: An enabled status means an alert configuration is active.
- Disabled: A disabled status means an alert configuration is disabled.
- Category: Select the category for the alert. Categories are groupings of supported alert types. The categories are Network, Platform, Site, User Experience, and Private Apps.
- Alert Type: Select the alert type. The alert types are Experience Score, Tunnel Status, Tunnel Flapping, Service Status, Site POP Connectivity, Site Application Performance, Site Application Availability, and Publisher Resource Consumption. To learn more about the alert types please, see Alert Types.
- Condition: Select the condition that must be met to trigger the alert.
- Severity Levels: Choose the severity level for the alert.
- Critical
- High
- Medium
- Low
- Informational
- Notification Method: Select the notification type that you want to be sent when the alert is triggered, resolved, disabled, deleted, or expired. To learn more about notification methods please see, Notification Methods.
- Email: Enter the email address where you want the notification to be sent in the email field.
- Webhook: To select a webhook, you must create a webhook before you configure an alert. If not, please create a webhook before you continue configuring your alert. After you have configured a webhook, you can select your configured webhook when configuring a new alert.
- Save button: Click the save button to save your new alert configuration.
Configure an Alert for Experience Score
Experience score alerts are designed to monitor and generate alerts for sustained drops in the DEM user experience score based on user group, OU, or geographic location.
For a user to qualify to match the Experience Score alert criteria and conditions they must have at least 3 DEM experience score data points that meet the experience score threshold collected in the time window specified, see below for time window details. Please ensure your data collection/measurement intervals are configured according to the time window specified. Example: 20 minute time window is configured in the alert configuration, an ideal collection and measurement interval would be every 5 minutes for device and network RTT metrics. To learn more, please see: Configure a Network Path Probe.
You can configure a new Experience Score alert by doing the following:
- To begin the configuration process for a new Experience Score alert, open the New Alert Configuration window.
- Define the alert name.
- Use the Status toggle to set the alert to enabled or disabled.
- For the category, select User Experience.
- For the alert type, select Experience Score.
- Select the User Group/OU (s) which contain the users for which you wish to monitor the user experience score. (User groups and OU’s can be selected together and will be considered using a logical OR operator)
- Select the geographic regions you wish to include in the alert criteria based on the fields below. (You can select a single geographic parameter such as country or State/Province without selecting city for large scope alerts)
- City
- State/Province
- Country
- Select the conditions:
- Score threshold
- Number of Users threshold
- Duration of sustained low score
- Select the severity to assign to the alert.
- Select the Notification Method:
- Email: Enter the email address where you want to send the alert notifications.
- Webhook: Select an existing webhook, or to create a new webhook, please read, How to Create a New Webhook.
- Click the Save button to create your new alert.
- You can view your saved alert configuration on the Alert Configurations page.
Configure an Alert for Site POP Connectivity
Site POP Connectivity alerts are designed to monitor the latency (based on the metric of your choice; Avg, P50, P75, P90, P99) between site(s) and the Netskope POPs observed being used. You can set a latency threshold and sustained duration as conditions.
You can configure a new Site POP Connectivity alert by doing the following:
- To begin the configuration process for a new Site POP Connectivity alert, open the New Alert Configuration window.
- Define the alert name.
- Use the Status toggle to set the alert to enabled or disabled.
- For the category, select Site.
- For the alert type, select Site POP Connectivity.
- Select the sites which you would like to monitor. (Multiple sites can be selected together and will be considered using a logical OR operator)
- Select the conditions:
- Mathematical aggregation type
- Latency threshold
- Duration of sustained latency observed
- Select the severity to assign to the alert.
- Select the Notification Method:
- Email: Enter the email address where you want to send the alert notifications.
- Webhook: Select an existing webhook, or to create a new webhook, please read, How to Create a New Webhook.
- Click the Save button to create your new alert.
- You can view your saved alert configuration on the Alert Configurations page.
Configure an Alert for Site Application Performance
Site Application Performance alerts are designed to monitor the latency (based on the metric of your choice; Avg, P50, P75, P90, P99) between site(s) and the application(s) chosen. You can set a latency threshold and sustained duration as conditions.
You can configure a new Site Application Performance alert by doing the following:
- To begin the configuration process for a new Site Application Performance alert, open the New Alert Configuration window.
- Define the alert name.
- Use the Status toggle to set the alert to enabled or disabled.
- For the category, select Site.
- For the alert type, select Site Application Performance.
- Select the sites which you would like to monitor. (Multiple sites can be selected together and will be considered using a logical OR operator)
- Select the applications which you would like to monitor. (Multiple applications can be selected together and will be considered using a logical OR operator)
- Select the conditions:
- Mathematical aggregation type
- Latency threshold
- Duration of sustained latency observed
- Select the severity to assign to the alert.
- Select the Notification Method:
- Email: Enter the email address where you want to send the alert notifications.
- Webhook: Select an existing webhook, or to create a new webhook, please read, How to Create a New Webhook.
- Click the Save button to create your new alert.
- You can view your saved alert configuration on the Alert Configurations page.
Configure an Alert for Site Application Availability
Site Application Availability alerts are designed to monitor the availability percentage of successful tests between site(s) and the application(s) chosen. You can set an availability threshold and sustained duration as conditions.
You can configure a new Site Application Performance alert by doing the following:
- To begin the configuration process for a new Site Application Availability alert, open the New Alert Configuration window.
- Define the alert name.
- Use the Status toggle to set the alert to enabled or disabled.
- For the category, select Site.
- For the alert type, select Site Application Availability.
- Select the sites which you would like to monitor. (Multiple sites can be selected together and will be considered using a logical OR operator)
- Select the applications which you would like to monitor. (Multiple applications can be selected together and will be considered using a logical OR operator)
- Select the conditions:
- Availability percentage threshold
- Duration of sustained breach observed
- Select the severity to assign to the alert.
- Select the Notification Method:
- Email: Enter the email address where you want to send the alert notifications.
- Webhook: Select an existing webhook, or to create a new webhook, please read, How to Create a New Webhook.
- Click the Save button to create your new alert.
- You can view your saved alert configuration on the Alert Configurations page.
Configure an Alert for Tunnel Status
Tunnel Status alerts can be configured to allow you to monitor the availability of the tunnels. You can choose to monitor all tunnels or a specific subset of tunnels. The selection can be made from a list that includes active primary and backup tunnels. Only tunnels that have an associated POP are available for selection.
You can configure a new Tunnel Status alert by doing the following:
- To begin the configuration process for a new Tunnel Status alert, open the New Alert Configuration window.
- Create an alert name.
- Use the Status toggle to set the alert to enabled or disabled. The Status toggle is set to enabled by default. Use the toggle to set an alert configuration status to disabled to disable it
- For the category, select Network.
- For the alert type, select Tunnel Status.
- Select the IPSec or GRE tunnels tab to choose the tunnels that you want the alert configuration to monitor.
An alert is triggered only if the GRE tunnel remains down for the configured duration, which should not be less than the Keep Alive probe frequency. If Keep Alive probes are not configured before setting up alerts, it can lead to an increase in false positives, making the alerts ineffective and inaccurate.
- View the tunnels available to be monitored by clicking the Tunnel = field.
- Select the tunnels that you want to monitor:
- To monitor all tunnels: Click the checkbox next to All Tunnels.
- To exclude specific tunnels: After clicking the checkbox to monitor all tunnels, an add exclusion field will appear below the original Tunnel = field. In the new field, select the tunnels that you would like to exclude by clicking the checkbox next to the name of the tunnels that you want to exclude.
- To monitor a specific selection of tunnels: Ensure that the All Tunnels checkbox is unchecked. Then, select the specific tunnels that you want to monitor by clicking the checkbox next to the name of each tunnel that you want to monitor
- Select the condition. This condition determines when an alert is triggered. You can select from a status down condition of between one to ten minutes.
- Select the severity level.
- Select the Notification Method:
- Email: Enter the email address where you want to send the alert notifications.
- Webhook: Select an existing webhook, or to create a new webhook, please read, How to Create a New Webhook.
- Click the Save button to create your new alert.
- You can view your saved alert configuration on the Alert Configurations page.
Configure an Alert for Tunnel Flapping
The alert configuration process for Tunnel Flapping alerts for IPSec tunnels is designed to monitor and provide alerts on the stability of network tunnels, and to identify when they frequently go up and down within a short period of time, which is a behavior known as “flapping”.
You can configure a new Tunnel Flapping alert by doing the following:
- To begin the configuration process for a new Tunnel Status alert, open the New Alert Configuration window.
- Create an alert name.
- Use the Status toggle to set the alert to enabled or disabled.
- For the category, select Network.
- For the alert type, select Tunnel Flapping.
- Select the IPSec or GRE tunnels tab to choose the tunnels that you want the alert configuration to monitor.
An alert is triggered only if the GRE tunnel remains down for the configured duration, which should not be less than the Keep Alive probe frequency. If Keep Alive probes are not configured before setting up alerts, it can lead to an increase in false positives, making the alerts ineffective and inaccurate.
- View the tunnels available to be monitored by clicking the Tunnel = field.
- Select the tunnels that you want to monitor:
- To monitor all tunnels: Click the checkbox next to All Tunnels.
- To exclude specific tunnels: After clicking the checkbox to monitor all tunnels, an add exclusion field will appear below the original Tunnel = field. In the new field, select the tunnels that you would like to exclude by clicking the checkbox next to the name of the tunnels that you want to exclude.
- To monitor a specific selection of tunnels: Ensure that the All Tunnels checkbox is unchecked. Then, select the specific tunnels that you want to monitor by clicking the checkbox next to the name of each tunnel that you want to monitor
- Select the condition. This setting determines how quickly an alert is generated after a tunnel goes down. You can select from status change in 5, 10, or 15 minutes.
- Select the severity.
- Select the Notification Method:
- Email: Enter the email address where you want to send the alert notifications.
- Webhook: Select an existing webhook, or to create a new webhook, please read, How to Create a New Webhook.
- Click the Save button to create your new alert.
- You can view your saved alert configuration on the Alert Configurations page.
Configure an Alert for Service Status
The Service Status Alerts are designed to inform customers about the operational state of services in a Point of Presence (POP) they utilize. These alerts serve as notifications about any issues that might impact user experiences. These alerts are primarily for informational purposes, and indicate when Netskope is addressing a service disruption by redirecting traffic or taking other mitigating actions. These actions often require no immediate action from customers.
You can configure a new Service Status alert by doing the following:
- To begin the configuration process for a new Tunnel Status alert, open the New Alert Configuration window.
- Create an alert name.
- Use the Status toggle to set the alert to enabled or disabled.
- For the category, select Platform.
- For the alert type, select Service Status.
- View the POPs available to be monitored by clicking the POPs= field.
- Select the POPs that you want to monitor by clicking the checkbox next to the name of the specific POP.
- Select the condition by clicking the Services = field to view the services and make your selections.
For IPSEC and GRE, please check your configuration to see if manual traffic steering is required.
- Select the severity.
- Select the notification Method:
- Email: Enter the email address where you want to send the alert notifications.
- Webhook: Select an existing webhook, or to create a new webhook, please read, How to Create a New Webhook.
- Click the Save button to create your new alert.
- You can view your saved alert configuration on the Alert Configurations page.
Configure an Alert for Publisher Resource Consumption
The Publisher Resource Utilization alert is designed to help you monitor and manage the resource consumption of your publishers effectively.
- To begin the configuration process for a new Publisher Resource Consumption alert, open the New Alert Configuration window.
- Create an alert name.
- Use the Status toggle to set the alert to enabled or disabled.
- For the category, select Private Apps.
- For the alert type, select Publisher Resource Consumption.
- View the publishers available to be monitored by clicking the Publishers = field.
- Select the publishers that you want to monitor:
- To monitor all publishers: Click the checkbox next to All Publishers.
- To exclude specific publishers: After clicking the checkbox to monitor all publishers, click +Exclusions, an add exclusion field will appear below the original Publishers = field. In the new field, select the publishers that you would like to exclude by clicking the checkbox next to the name of the publishers that you want to exclude.
- To monitor a specific selection of publishers: Ensure that the All Publishers checkbox is unchecked. Then, select the specific publishers that you want to monitor by clicking the checkbox next to the name of each publisher that you want to monitor.
- Select the condition by clicking the checkboxes next to the conditions that you want to select:
- CPU Usage: An alert can be set to trigger if CPU usage exceeds a certain percentage (x%) within a specified time frame. Measurements are taken every fifth minute.
- Memory Usage: Similar to CPU, an alert can be configured for memory usage exceeding a certain threshold (X%) within a given time (t minutes). Measurements are taken every fifth minute.
- Storage Usage: For storage, the condition is set to trigger an alert if usage meets or surpasses a set percentage (X%) within the defined time. Measurements are taken every fifth minute.
- Select the severity.
- Select the notification Method:
- Email: Enter the email address where you want to send the alert notifications.
- Webhook: Select an existing webhook, or to create a new webhook.
- Click the Save button to create your new alert.
- You can view your saved alert configuration on the Alert Configurations page.

