Configure File IQ Alerts and Email Notifications

Prev Next

Overview of File IQ Alerts

The Nasuni File IQ Alerting feature offers proactive visibility into volume usage, performance, and structural changes. Administrators can configure alerts to receive timely notifications of unusual activity or potential issues, providing proactive insights into your Edge Appliances and volumes.

Email alerts are available for both volume processing and activity events.

Note: A Nasuni File IQ Premium license is required to enable the Nasuni File IQ Alerting feature.

Activity Alerts

Activity Alerts monitor file and user activity, highlighting anomalies or significant changes so teams can respond quickly. By default, Grafana evaluates activity alerts every 5 minutes, with customizable intervals available through the alert configuration page.

The supported alerts include the following:

  • Activity – Edge Appliance Throughput Alert

  • Activity – Volume Delete Events Alert

  • Activity – Volume Write Events Alert

  • Activity - Volume Throughput Alert (File IQ version 10.4.2+)

  • Activity - Honeypot Files Alert (File IQ version 10.4.2+)

  • Activity - IP Subnet Alert (File IQ version 10.4.2+)

  • Activity - Presence of Extension Type Alert (File IQ version 10.4.2+)

  • Activity - In Directory Alert (File IQ version 10.4.2+)

Volume Alerts

Volume Alerts provide scheduled insights into storage usage, including file count and total volume size. By default, these alerts are generated weekly, but the frequency can be customized through the alert configuration page. Volume Alerts help teams track storage utilization, identify usage, and trends.

The supported alerts available include the following:

  • Volume Processing - Volume File Count Increase Alert

  • Volume Processing - Volume Size Increase Alert

How File IQ Alerts Work

This section provides an overview of the File IQ Alert concepts and logic.

Rules

Alert rules define the specific conditions that trigger an alert notification. When activity or usage exceeds a predefined threshold, such as a spike in write events or an increase in file count, an automated email alert is sent. These rules can be easily configured within the Nasuni File IQ interface and include the following elements:

  • Name: A unique identifier for the alert rule.

  • Condition: The criteria that determine when the alert is triggered, such as "Number of Write events > 80%".

  • Interval: How often the alert condition is evaluated (See the Time Intervals section below for details).

Instances

Alert instances refer to the specific occurrences that trigger an alert rule. They are created when the alert rule's conditions are met. The key details of an alert instance include the following:

  • Alert Name: The name of the alert rule that triggered the instance.  

  • Status: The current state of the alert instance, which can be:

    • Firing: The alert condition is currently true.

    • Resolved: The alert’s rule condition is no longer true.

  • Start Time: The timestamp indicating when the alert condition was first met.

  • End Time: The timestamp indicating when the alert condition was resolved (if applicable).

Time Intervals

File IQ Alerting uses three types of time intervals to manage how and when alerts are evaluated and sent:

Evaluation Interval: The frequency at which the system checks whether an alert condition is met. File IQ checks alert conditions periodically according to this interval.

Alert Interval: This defines the timeframe used to evaluate the data. For example, a 10-minute window means the system examines the most recent 10 minutes of activity to determine whether the alert condition is met.

Repeat-After Interval: This sets how long the system waits before sending the same alert again. Even if the condition still exists, no new alert will be sent until this time period has passed, helping prevent duplicate notifications.

The example below demonstrates the following:

  • Evaluation Interval: 5 minutes

  • Alert Interval: 10 minutes

  • Repeat After Interval: 4 hours

The following table details the value for these three intervals for Activity and Volume alerts:

Interval

Activity Alerts

Volume Alerts

Evaluation Interval

Always 5 minutes

Interval between the previous successful scan and the current one, usually around 24 hours

Alert Interval

Configurable in seconds in the alert configuration popup (Interval field), 5 minutes by default

Configurable in days in the alert configuration popup (Interval field), 7 days by default

Repeat After Interval

Configurable in minutes in the alert configuration popup (Repeat After field), 5 minutes by default

Configurable in minutes in the alert configuration popup (Repeat After field), 1440 minutes by default (1 day)

Adjusting Email Notification Frequency

You can control how often you receive email notifications for alerts by modifying the Repeat After Interval setting.

This setting defines the minimum time (in minutes) between repeated notifications for a single alert. It helps reduce noise by instructing the system, “Only send another alert if this condition is still true after a set amount of time has passed”.

Note: The Evaluation Interval occurs every 5 minutes. If the Repeat After Interval matches or is a multiple of the Evaluation Interval, notification timing might align with the next scheduled evaluation. As a result, alerts might not always be sent exactly after the specified interval.

Tips for Managing Notification Frequency

  • To receive more frequent reminders: Decrease the Repeat After Interval to get more frequent notifications when an alert remains active (firing) over time.

  • To reduce the number of emails: Increase the Repeat After Interval to limit the number of reminder notifications for ongoing (firing) alerts.

Adjusting this setting allows you to strike the right balance between staying informed and minimizing email noise.

Prerequisites and Setup

To use the File IQ Alerting feature, you must have a Nasuni File IQ appliance managed through the Nasuni Management Console (NMC) version 25.2 or above, and an active Nasuni File IQ Premium license.

Once these prerequisites are met, complete the following steps to enable alerting:

  • Configure a group of email recipients.

  • Enable your desired Alerts.

  • Send test email.

  • Configure and enable individual alerts.

Note: All Nasuni File IQ alert rules are disabled by default.

Configure Email Recipients in NMC

The alert email recipient list is created in the Nasuni Management Console. This section describes the process of creating a dedicated group for alert emails, or alternatively, enabling an existing group to be notified.

Creating a Dedicated Group for Nasuni File IQ Alerts

To configure a dedicated alert email group for Nasuni File IQ alerts, follow these steps:

  1. Navigate the NMC UI.

  2. Click the Console Settings tab.

  3. From the left side menu, click the Users/Groups option.
     

  4. Click Manage Groups.

  5. Click Add Group.

  6. Enter a Group Name.

  7. For Access Type, select User Interface Access.

  8. In the Filer Permissions section, ensure that Receive Filer alert emails is selected.

  9. In the Email Subscriptions section, select Nasuni File IQ Alerts.

  10. (Optional) To configure alerts for users who are not in the system, add their email addresses to the Extra Emails field.

  11. In the Filer Access section, grant access to the Nasuni File IQ Appliance.

  12. Click Add Group to finish.

Enabling Alerts for an Existing Group

To enable alert emails for an existing group, follow these steps:

  1. Navigate the NMC UI.

  2. Click the Console Settings tab.

  3. From the left side menu, click the Users/Groups option.

  4. Click Manage Groups.

  5. For every group receiving File IQ Report Ready alerts, click the edit icon.
     

  6. In the Filer Permissions section, ensure that Receive Filer alert emails is selected.

    Note: If Manage all aspects of the Filer is selected, Nasuni File IQ Alerts is implicitly selected.

  7. In the Email Subscriptions section, select Nasuni File IQ Alerts.
     

  8. (Optional) To configure alerts for users who are not in the system, add their email addresses to the Extra Emails field.

    Note: Individuals added to this field receive alerts for all configured alert types. If this is not desirable, consider creating a dedicated group for reporting alerts.

  9. Click Save Group.

Enable File IQ Alerts

Navigate to the Enable File IQ Alerts page to enable and configure your desired alerts. After enabling your alerts, proceed to the Send a Test Email Alert section to confirm your setup.

Send a Test Alert Email

After setting up the email recipient group and enabling the alerting feature, you can send a test email to verify that the configuration is working correctly.

To send a test email:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Go to the Configuration tab and select Alerts Configuration.

  3. Click the Send Test Email button.

An email request will be sent to the NMC, and a confirmation message will appear in the top-right corner of the File IQ user interface:

The test email typically arrives within one minute. If you do not receive the email, check the following:

  • Your spam or junk folder.

  • That the email notification group is correctly configured as described above.

  • (Optional) That your email address is added to the Extra Emails field if your user is not listed in the system.

  • That the NMC email configuration is correctly set up.

You can find more information on configuring SMTP settings in the Email Settings section of the Nasuni Management Console documentation.

Also, verify that there are no error notifications in the NMC related to email delivery.

If the issue persists, contact your IT support team for further assistance.

You can customize the footer that appears at the bottom of the File IQ alert emails. Footer customization is available in two ways:

  • Per alert rule.

  • Globally (for all alert rules).

When using both types of footers, the email displays the per-alert footer first, followed by the global footer.

To customize the footer for all alerts, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Use the Alert Footer box to enter your footer text.

  4. Click Save.

To customize the footer for an individual alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Scroll down to the Nasuni File IQ Alerts section.

  4. Find the alert for which you want to configure a custom footer and click the corresponding Edit.

  5. Use the Alert Footer Text box to enter your footer text.

  6. Click Save.

Appendix B: Resetting Alerts to the Default Configuration

Resetting an alert restores it to its original default settings. This action disables the alert and removes any custom configurations you’ve applied.

To reset an individual alert:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Scroll down to the Nasuni File IQ Alerts section.

  4. Find the alert you want to reset, then click the corresponding Reset.

  5. (Optional) To reset all alerts at once, click Reset All Alerts Configuration.

Appendix C: Upgrade Behavior — Migrating from Single-Threshold to Per-Entity Alerting

When upgrading from a release that used a single global threshold to version 10.4+, which supports per-entity (per-Volume or per-NEA) thresholds, the following behavior is guaranteed:

  • The alerting feature remains enabled if it was enabled before the upgrade.

  • Each individual alert remains enabled if it was enabled before the upgrade.

  • All volumes or NEAs associated with an alert are automatically enrolled — every volume (or NEA) that existed at the time of the upgrade has the alert enabled.

  • The threshold value is preserved — the threshold configured before the upgrade is used as the initial threshold for every entity. For example, if the write events threshold was 8%, each volume starts with an 8% threshold after the upgrade.

Note: Although enrolling all entities may result in some false positives initially, this is preferable to disabling alerts and risking missed detections. Any false positive activity prompts you to review and adjust per-entity thresholds to better match each volume or NEA's individual usage profile.

Appendix D: Show Configuration Summary

The Show Configuration Summary button, located in the top-right corner of the alert list, provides a complete view of the current configuration across all alerts and all entities in a single consolidated table.

Overview

To open the configuration summary, click the Show Configuration Summary button in the top-right corner of the alert list.

This view is useful for auditing and reviewing the state of your alerting setup at a glance, without opening each alert individually.

The summary table displays the following information for each configured entity:

  • Alert Name: The name of the alert rule.

  • Alert Status: Whether the alert is currently enabled or disabled.

  • Interval: The configured alert interval.

  • Repeat After: The repeat-after interval configured for the alert.

  • Footer: The per-alert footer text, if configured.

  • Webhook Enabled: Whether webhook notifications are enabled for the alert.

  • Entity Friendly Name: The display name of the Volume or Edge Appliance (NEA) associated with the alert.

  • Entity Alert Status: Whether the alert is enabled for that specific entity.

  • Threshold: The threshold value configured for that entity.

Filtering the Configuration Summary

The table supports filtering to help narrow down the displayed results. You can filter by any combination of the following:

  • Alert Status: Show only enabled or disabled alerts.

  • Alert Name: Filter to a specific alert type (for example, Volume Write Events Alert).

  • Entity Friendly Name: Search for a specific Volume or NEA by name.

  • Entity Alert Status: Show only entities where the alert is enabled or disabled.

Exporting the Configuration Summary

The configuration summary can be exported to a CSV file, providing a portable record of the full alerting configuration across all alerts and entities.

Note: The Alert Configuration Summary CSV export fails if any alerts are configured with special characters.

To export the configuration summary to CSV, follow these steps:

  1. Click Show Configuration Summary located in the top-right corner of the alert list.

  2. (Optional) Apply any filters to narrow down the results before exporting.

  3. Click Download CSV to download the configuration summary as a CSV file.

Field

Recommended max per entity

IP subnets

20 per NEA

Directory

20 per volume, 20 sub-folders each

Extensions

40 per volume

Groups

100 per volume

Users

100 per volume/alert entity