Skip to main content

Alarm Customization

Alarm Customization allows you to customize certificate alarms based on much more detailed criteria. With this feature, you can create special alarm rules for certificates with specific characteristics and send different alarm notifications to different teams.

Access Path

You can access alarm customization configurations from the Alarm Configuration tab on the Discovery β†’ Expiry List & Alarm page.

What is Alarm Customization?​

Alarm Customization allows you to create much more granular and specific alarm rules beyond standard alarm configuration. This enables you to:

  • Scope-based alarms: Separate alarms for servers or certificates
  • Type-based alarms: Separate rules for server or CA certificates
  • Network Type filtering: Only certificates from external, local, or specific network types
  • Certificate Owner filtering: Special alarms for certificates owned by specific owners
  • Key Size warnings: Automatic notifications for insecure key sizes
  • Expired certificates: Separate notifications for expired certificates
  • Self-signed checking: Special rules for self-signed certificates

Alarm Customization List​

Alarm Customization List

Alarm Customization - Existing Rules

List Information​

On the list page, you can see all defined custom alarm rules:

  • Type - Alarm type (Subject, Issuer)
  • Scope - Scope (Server, Certificate)
  • Discover Type - Discovery type (Network, TLS, etc.)
  • Network Type - Network type filter (All, External, Internal)
  • Threshold Day - How many days in advance to send alarm
  • Certificate Owner - Certificate owner filter (Yes/No)
  • To Mails - Email addresses to receive notifications

List Operations​

You can perform the following operations for each row:

  • Edit - ✏️ Edit existing rule
  • Delete - πŸ—‘οΈ Delete rule
New Rule

Click the Create button to create a new custom alarm rule.

Creating New Alarm Customization Rule​

New Alarm Customization

Add New Alarm Customization Rule Form

Configuration Parameters​

Basic Filters​

ParameterDescriptionOptions
ScopeDetermines the scope in which the alarm will operateβ€’ Server: Separate notification for each server
β€’ Certificate: Notification for unique certificates
TypeSelect the type of certificates for which alarms will be createdβ€’ Subject: Server certificates
β€’ Issuer: CA certificates
Discover TypeFilter by how certificates were discoveredβ€’ Network: Network scanning
β€’ TLS: TLS connection
β€’ File: File system
Network TypeSelect the network type for which alarms will be createdβ€’ All: All network types
β€’ External: External certificates only
β€’ Internal: Internal certificates only
β€’ Custom types defined in Network Configuration

Alarm Rules​

ParameterDescriptionOptions
Send Alarm If Certificate Expires inDetermines how many days before certificate expiration to send alarmEnter number of days (e.g., 30, 15, 7)
Send Expired CertificatesShould notifications be sent for expired certificates?β€’ Yes: Notify for expired certificates as well
β€’ No: Only non-expired certificates
Key Size AlertWarning for insecure key sizesβ€’ Yes: Warning for small key sizes (e.g., 1024-bit RSA)
β€’ No: Don't check key size
Send Self-Signed CertificateShould self-signed certificates be included?β€’ Yes: Notify for self-signed as well
β€’ No: Exclude self-signed
Certificate OwnerFilter for certificates owned by specific ownersβ€’ Yes: Only certificates with specific owners
β€’ No: All certificates

Notification Settings​

ParameterDescriptionOptions
Alarm PeriodHow frequently notifications will be sentβ€’ Daily: Every day
β€’ Weekly: Weekly
HourWhat time notifications will be sent24-hour format (e.g., 10:00)
To MailEmail addresses to receive notificationsMultiple email addresses can be added (with Add More)
CcCopy recipients (optional)Multiple email addresses can be added
Mail SubjectEmail subject lineEnter email subject
Mail TextEmail contentEnter email content

Saving Configuration​

After filling in all fields, click the Submit button to save the rule.

Successful Save

After the rule is saved, automatic notifications will start being sent for certificates matching the specified criteria.