Enable File IQ Alerts

Prev Next

Before enabling a File IQ Alert, you must configure the File IQ Alerts and Email Notifications functionality.

Note: A Nasuni File IQ Premium license is required to enable the Nasuni File IQ Alerting feature.

Note: Beginning in File IQ version 10.4.1+, customers can configure all alerts on a per-volume or per-appliance basis.

Nasuni File IQ Alerts are divided into two primary categories: activity alerts and volume processing alerts. This section details each available alert, its purpose, parameters, and configuration.

Activity – Edge Appliance Throughput Alert

The File IQ Edge Appliance Throughput Alert detects when a significant number of file system audit events occur over a specified period across all Edge Appliances configured to forward their audit events to the Nasuni File IQ Appliance.

Configuration

To configure the Edge Appliance Throughput Alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Under the Nasuni File IQ Alerts section, locate the Edge Appliance Throughput Alert and click the corresponding Edit button.

  4. Check the Enable Alert box.

  5. (Optional) For customers on File IQ version 10.2+, check the Enable Webhook box to send alert notifications to a configured webhook endpoint in addition to email.

  6. Use the provided fields to enter an Interval, Threshold, Repeat After, and optional Footer Alert Text. The following table provides additional parameter information.

Parameter Name

Unit

Description

Min. Value

Max. Value

Default Value

Interval

Seconds

Alert Interval used for alert detection (seconds)

300

900

300

Threshold

Number of file system events

Number of events seen before alert fires

0

922000000000000000

60000

Repeat After

minutes

Resends an alert notification if not resolved within the selected time interval (minutes)

5

922000000000000000

5

Footer Alert Text

text

Custom text for alert email footer

0 Characters

255 Characters

Empty

  1. For customers on File IQ versions on 10.3.x and earlier, click Save. For customers on version 10.4.1+, continue to the Edge Appliance Settings.

  2. Under the Edge Appliance Settings, check the Enabled box for the Edge Appliances you want to monitor from the list. You can apply the same threshold to all selected Edge Appliances or configure each one individually.

    Alternatively, to bulk edit multiple Edge Appliances, follow these steps:

    1. Select the checkbox next to each Edge Appliance you want to update, or use the Select All checkbox at the top of the list to select all.

    2. Click Edit X Edge Appliance in the top-right corner of the table. A compact form appears.

    3. Check the Enable box and enter a Threshold.

    4. Click Apply.

  3. Click Save.

Email Notification

An email is sent as soon as the alert firing status changes, and then according to Repeat After Interval as long as it remains active.

These alerts include the following information:

  • Alert Name: The alert name and the number of instances with status changes are provided in the email subject.

  • Alert notification details: Provided as part of the email body:

    • Nasuni File IQ Appliance name exceeding the event threshold.

    • Number of events.

    • Alert status.

    • When the alert fired (UTC).

    • Alert resolution (UTC).

      Note: If unresolved, this field is empty.

  • Alert Description: A brief description of the alert.

  • Configuration Summary: Key parameters used in the alert configuration include:

    • Interval: Alert Interval used for the alert detection.

    • Threshold: Number of events observed before the alert fires.

    • Repeat After: Resends an alert notification if not resolved within the selected time interval.

  • Dashboard Link: A link to the Nasuni File IQ Inspector dashboard.

Activity – Volume Delete Events Alert

The File IQ Volume Delete Events Alert monitors each volume for high levels of file deletions within a defined time period. It helps identify high delete activity so you can take action quickly.

Configuration

To configure the Volume Delete Events Alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Under the Nasuni File IQ Alerts section, locate the Volume Delete Events Alert and click the corresponding Edit button.

  4. Check the Enable Alert box.

  5. (Optional) For customers on File IQ version 10.2+, check the Enable Webhook box to send alert notifications to a configured webhook endpoint in addition to email.

  6. Use the provided fields to enter an Interval, Threshold, Repeat After, and optional Footer Alert Text. The following table provides additional parameter information.

Parameter Name

Unit

Description

Min. Value

Max. Value

Default Value

Interval

Seconds

Alert Interval used for the alert detection.

300

900

300

Threshold

Number of delete events

Number of delete events seen before the alert fires.

0

922000000000000000

100

Repeat After

Minutes

Resends an alert notification if not resolved within the selected time interval

5

922000000000000000

5

Footer Alert Text

Text

Custom text for alert email footer

0 Characters

255 Characters

Empty

  1. For customers on File IQ versions on 10.3.x and earlier, click Save. For customers on version 10.4.1+, continue to the Volume Settings.

  2. Under the Volume Settings, check the Enabled box for the volumes you want to monitor from the list. You can apply the same threshold to all selected volumes or configure each one individually.

    Alternatively, to bulk edit multiple volumes, follow these steps:

    a. Select the checkbox next to each volume you want to update, or use the Select All checkbox at the top of the list to select all.

    b. Click Edit X Volumes in the top-right corner of the table. A compact form appears.

    c. Check the Enable box and enter a Threshold.

    d. Click Apply.

  3. Click Save.

Email Notification

An email is sent as soon as the alert firing status changes, and then according to Repeat After Interval as long as it remains active.

These alerts include the following information:

  • Alert Name: The alert name and the number of instances with status changes are provided in the email subject.

  • Alert notification details: Provided as part of the email body:

    • Nasuni volume names exceeding the event threshold.

    • Number of events.

    • Alert status.

    • When the alert fired (UTC).

    • When the alert resolved (UTC).

      Note: If unresolved, this field is empty.

  • Alert Description: A brief description of the alert.

  • Configuration Summary: Key parameters used in the alert configuration.

    • Interval: Interval used for alert detection.

    • Threshold: Number of delete events observed before the alert fires.

    • Repeat After: Resends an alert notification if not resolved within the selected time interval.

  • Dashboard Link: A link to the Nasuni File IQ Inspector dashboard.

Activity – Volume Write Events Alert

The Volume Write Events Alert tracks each volume for high write activity over a set time period. It allows you to investigate and respond as needed.

Configuration

To configure the Volume Write Events Alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Under the Nasuni File IQ Alerts section, locate the Volume Write Events Alert and click the corresponding Edit button.

  4. Check the Enable Alert box.

  5. (Optional) For customers on File IQ version 10.2+, check the Enable Webhook box to send alert notifications to a configured webhook endpoint in addition to email.

  6. Use the provided fields to enter an Interval, Threshold, Minimum Volume Size, Minimum of Write Events, Repeat After, and optional Footer Alert Text. The following table provides additional parameter information.

Parameter Name

Unit

Description

Min. Value

Max. Value

Default Value

Interval

Seconds

Alert Interval used for the alert detection

300

900

300

Threshold

Percentage

Percentage increase of write events seen before alert fires

0

100

8

Minimum Volume Size

GB

Applies the alert to volume(s) with the specified minimum size

0

922000000000000000

100

Minimum of write events

Number of write events

Applies the alert to volume(s) with the minimum number of write events for the selected interval

0

922000000000000000

60000

Repeat After

Minutes

Resends an alert notification if not resolved within the selected time interval

5

922000000000000000

5

Footer Alert Text

Text

Custom text for alert email footer

0 Characters

255 Characters

Empty

  1. For customers on File IQ versions on 10.3.x and earlier, click Save. For customers on version 10.4.1+, continue to the Volume Settings.

  2. Under the Volume Settings, check the Enabled box for the volumes you want to monitor from the list. You can apply the same threshold to all selected volumes or configure each one individually.

    Alternatively, to bulk edit multiple volumes, follow these steps:

    a. Select the checkbox next to each volume you want to update, or use the Select All checkbox at the top of the list to select all.

    b. Click Edit X Volumes in the top-right corner of the table. A compact form appears.

    c. Check the Enable box and enter a Threshold.

    d. Click Apply.

  3. Click Save.

Email Notification

An email is sent as soon as the alert firing status changes, and then according to Repeat After Interval, as long as it remains active.

These alerts include the following information:

  • Alert Name: The alert name and the number of instances with status changes are provided in the email subject.

  • Alert notification details: Provided as part of the email body:

    • Nasuni volume names that exceed the event threshold.

    • Percentage difference.

    • Alert status.

    • When the alert fired (UTC).

    • When the alert resolved (UTC).

    • Note: If unresolved, this field is empty.

  • Alert Description: A brief description of the alert.

  • Configuration Summary: Key parameters used in the alert configuration.

    • Interval: Interval used for alert detection.

    • Threshold: Percentage increase of write events observed before the alert fires.

    • Minimum Volume Size: Applies the alert to volumes with the specified minimum size.

    • Minimum Number of write events: Applies the alert to volumes with the minimum number of write events for the selected interval.

    • Repeat After: Resends an alert notification if not resolved within this selected time interval.

  • Dashboard Link: A link to the Nasuni File IQ Inspector dashboard.

Match-Based and Threshold-Based Activity Alerts

Beginning in File IQ version 10.4.1+, the following five activity alerts extend the Nasuni File IQ Alerting feature with deeper, per-entity activity detection based on audit event stream data. Each alert is evaluated independently and can be configured per volume or per Edge Appliance (NEA).

Four of the alerts use match-based detection. A match-based alert is triggered immediately after an audit event matches the configured criteria within the evaluation window. These criteria include activity on designated honeypot files, activity from client IP addresses within specified subnets, activity involving specific file extensions, or activity within specific directories. Because any single matching event triggers an alert, these alerts detect activity that should never occur, regardless of frequency. The system records the number of matching events and exposes the details in the Alerting Inspector dashboard for investigation.

The Volume Throughput Alert uses threshold-based detection. The alert triggers after the total number of audit events on a volume exceeds a configured threshold within the evaluation window. This detection behaves the same as the activity alerts available in versions 10.3.x and earlier.

The match-based alerts support filtering through a target mode or subnet mode, and include the following options:

  • Any: Alert for activity from any user or group. No filtering is applied.

  • Include: Alerting applies only to specified users, groups, or subnets.

  • Exclude: Alerting applies to all activity except the specified users, groups, or subnets.

Note: Text input fields in these alerts support multiple values separated only by semicolons.

Alert

Scope

Detection Method

Alert Type

Activity – Volume Throughput Alert

Per Volume

Audit Events

Threshold-based

Activity – Honeypot Files Alert

Per Volume

Audit Events

Match-based

Activity – IP Subnet Alert

Per Edge Appliance (NEA)

Audit Events (SMB/CIFS only)

Match-based

Activity – Presence of Extension Type Alert

Per Volume

Audit Events

Match-based

Activity – In Directory Alert

Per Volume

Audit Events

Match-based

Activity – Volume Throughput Alert

The Volume Throughput Alert detects when the total number of audit event file system operations on a volume exceeds a configured threshold within a defined time window.

Configuration

To configure the Volume Throughput Alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Under the Nasuni File IQ Alerts section, locate the Volume Throughput Alert and click the corresponding Edit button.

  4. Check the Enable Alert box.

  5. (Optional) Check the Enable Webhook box to send alert notifications to a configured webhook endpoint in addition to email.

  6. Use the provided fields to enter an Interval, Repeat After, and optional Footer Alert Text. The following table provides additional parameter information.

Parameter Name

Type

Unit

Desription

Min. Value

Max. Value

Interval

Base Setting

Seconds

Alert Interval used for alert detection.

300

900

Repeat After

Base Setting

Minutes

Resends an alert notification if not resolved within the selected time interval.

5

922000000000000000

Footer Alert Text

Base Setting

Text

Custom text for alert email footer.

0 Characters

255 Characters

Threshold

Per Entity Setting

Number of file system events

Number of events on the Volume before the alert fires.

0

922000000000000000

  1. Under the Volume Settings, check the Enabled box for the volumes you want to monitor from the list. You can apply the same threshold to all selected volumes or configure each one individually.

    Alternatively, to bulk edit multiple volumes, follow these steps:

    a. Select the checkbox next to each volume you want to update, or use the Select All checkbox at the top of the list to select all.

    b. Click Edit X Volumes in the top-right corner of the table. A compact form appears.

    c. Check the Enable box and enter a Threshold.

    d. Click Apply.

  2. Click Save.

Email Notification

An email is sent as soon as the alert firing status changes, and then according to the Repeat After Interval as long as it remains active.

These alerts include the following information:

  • Alert Name: The alert name and the number of instances with status changes are included in the email subject line.

  • Alert notification details: Provided as part of the email body:

    • Nasuni volume names exceeding the event threshold.

    • Number of events observed.

    • Alert status.

    • When the alert fired (UTC).

    • When the alert resolved (UTC) — empty if unresolved.

  • Alert Description: A brief description of the alert.

  • Shared Configuration: Settings that apply across all monitored Volumes:

    • Interval: Alert Interval used for alert detection.

    • Repeat After: Resends an alert notification if not resolved within the selected time interval.

  • Entity Configuration: A table listing each monitored Volume and its individually configured threshold:

    • Volume: The name of the Volume.

    • Threshold: Number of events observed before the alert fires for that Volume.

  • Dashboard Link: A link to the Nasuni File IQ Inspector dashboard.

Activity – Honeypot Files Alert

The Honeypot Files Alert detects any audit event activity on files that you have designated as honeypot files for a volume. It fires as soon as a matching event is received within the evaluation window, with optional user and group filtering.

A honeypot file is a file placed in a location where it should never normally be accessed, or only accessed by a cohort of intended people. Any access to it (or access from unexpected users) might indicate suspicious or unauthorized activity.

Configuration

To configure the Honeypot Files Alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Under the Nasuni File IQ Alerts section, locate the Honeypot Files Alert and click the corresponding Edit button.

  4. Check the Enable Alert box.

  5. (Optional) Check the Enable Webhook box to send alert notifications to a configured webhook endpoint in addition to email.

  6. Use the provided fields to enter the Interval for alert detection, Resend if not resolved after, and optional Footer Alert Text. The following table provides additional parameter information.

Parameter Name

Type

Unit

Description

Min. Value

Max. Value

Interval

Base Setting

Seconds

Alert Interval used for alert detection

300

900

Repeat After

Base Setting

Minutes

Resends an alert notification if not resolved within the selected time interval

5

922000000000000000

Footer Alert Text

Base Setting

Text

Custom text for alert email footer

0 Characters

255 Characters

Webhook Enabled

Base Setting

Toggle

Sends alert notifications to a configured webhook endpoint

-

-

Files

Per Entity Setting

File Paths

List of file paths to monitor per Volume, separated by semicolons

At least 1 path

-

Users

Per Entity Setting

User Names

Users to include or exclude from alerting, separated by semicolons (used with Include / Exclude mode)

-

-

Groups

Per Entity Setting

Group Names

Groups to include or exclude from alerting, separated by semicolons (used with Include / Exclude mode)

-

-

Target

Per Entity Setting

Any / Include / Exclude

Determines whether all users/groups are considered, or the list is inclusive or exclusive

-

-

  1. Under the Volume Settings, check the Enabled box for the volumes you want to monitor from the list. You can apply the same settings to all selected volumes or configure each one individually.

  2. Enter the following information:

    - Files: Enter the full file paths to each file to be monitored as honeypot files for that volume, separated by a semicolon (for example, /folder/report.pdf; /image.png; /folder/sub-folder/data.csv). Wildcards are not supported. Each path must be an exact match.

    - Target: (Optional) Configure a target filter to control which users and groups are considered for the alert.

    - Users and Groups: Enter user names or group names separated by a semicolon in the respective fields (for example, user1; DOMAIN\user2; DOMAIN\group name). User names and group names are only required when using Include or Exclude mode.

    Alternatively, to bulk edit multiple volumes, follow these steps:

    a. Select the checkbox next to each volume you want to update, or use the Select All checkbox at the top of the list to select all.

    b. Click Edit X Volumes in the top-right corner of the table. A form appears.

    c. Check the Enable box and enter your desired values. Use the table above as a reference.

    d. Click Apply.

  3. Click Save.

Email Notification

An email is sent as soon as the alert firing status changes, and then according to the Repeat After Interval, as long as it remains active.

These alerts include the following information:

  • Alert Name: The alert name and the number of instances with status changes are included in the email subject line.

  • Alert notification details:

    • Names of Volumes where honeypot activity was detected.

    • Number of matching events detected.

    • Alert status.

    • When the alert fired (UTC).

    • When the alert resolved (UTC) — empty if unresolved.

  • Alert Description: A brief description of the alert.

  • Shared Configuration: Settings that apply across all monitored Volumes:

    • Interval: Alert Interval used for alert detection.

    • Repeat After: Resends an alert notification if not resolved within the selected time interval.

  • Dashboard Link: A link to the Alerting Inspector dashboard to investigate the matching events in detail, including the files accessed, the user, group, and event type involved.

Activity – IP Subnet Alert

The IP Subnet Alert detects audit event activity from client IP addresses according to a configured subnet list for an Edge Appliance (NEA). It supports three modes: alert for any IP address (Any), alert only for listed subnets (Include), or alert for all subnets except listed ones (Exclude).

Note: This alert applies only to SMB/CIFS audit events. Client IP address data is not included in NFS audit events. Additionally, Linux kernels cache NFS read data, which means repeated reads of the same file might not generate additional audit events.

Configuration

To configure the IP Subnet Alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Under the Nasuni File IQ Alerts section, locate the IP Subnet Alert and click the corresponding Edit button.

  4. Check the Enable Alert box.

  5. (Optional) Check the Enable Webhook box to send alert notifications to a configured webhook endpoint in addition to email.

  6. Use the provided fields to enter the Interval for alert detection, Resend if not resolved after, and optional Footer Alert Text. The following table provides additional parameter information.

Parameter Name

Type

Unit

Description

Min. Value

Max. Value

Interval

Base Setting

Seconds

Alert Interval used for alert detection

300

900

Repeat After

Base Setting

Minutes

Resends an alert notification if not resolved within the selected time interval

5

922000000000000000

Footer Alert Text

Base Setting

Text

Custom text for alert email footer

0 Characters

255 Characters

Webhook Enabled

Base Setting

Toggle

Sends alert notifications to a configured webhook endpoint

-

-

Subnets

Per Entity Setting

CIDR notation

List of IP subnets to monitor per NEA, separated by semicolons (used with Include / Exclude mode)

-

-

Target

Per Entity Setting

Any / Include / Exclude

Determines whether all IP addresses are considered, or the subnet list is inclusive or exclusive

-

-

  1. Under the Edge Appliance Settings, check the Enabled box for the Edge Appliances you want to monitor from the list. You can apply the same settings to all selected Edge Appliances or configure each one individually.

  2. Enter the following information:

    - Target: (Optional) Configure a target filter to control which users and groups are considered for the alert.

    - IP Subnets: Enter the IP subnets to monitor for that NEA in CIDR notation, separated by a semicolon (for example, 192.168.1.0/24; 10.0.0.0/8). A single IP address without a subnet mask (for example, 10.0.0.1) is treated as a /32 entry.

    Alternatively, to bulk edit multiple Edge Appliances, follow these steps:

    a. Select the checkbox next to each Edge Appliance you want to update, or use the Select All checkbox at the top of the list to select all.

    b. Click Edit X Edge Appliances in the top-right corner of the table. A form appears.

    c. Check the Enable box and enter your desired values. Use the table above as a reference.

    d. Click Apply.

  3. Click Save.

Email Notification

An email is sent as soon as the alert firing status changes, and then according to the Repeat After Interval as long as it remains active.

These alerts include the following information:

  • Alert Name: The alert name and the number of instances with status changes are provided in the email subject.

  • Alert notification details: Provided as part of the email body:

    • Names of Edge Appliances where matching subnet activity was detected.

    • Number of matching events detected.

    • Alert status.

    • When the alert fired (UTC).

    • When the alert resolved (UTC) — empty if unresolved.

  • Alert Description: A brief description of the alert.

  • Shared Configuration: Settings that apply across all monitored Edge Appliances:

    • Interval: Alert Interval used for alert detection.

    • Repeat After: Resends an alert notification if not resolved within the selected time interval.

  • Dashboard Link: A link to the Alerting Inspector dashboard to investigate the matching events in detail, including the client IP addresses, paths, users, and event types involved.

Activity – Presence of Extension Type Alert

The Presence of Extension Type Alert detects audit event activity involving files with configured file extensions on a Volume. It supports composite extensions (for example, .tar.gz is treated as distinct from .gz), with optional user and group filtering.

Configuration

To configure the Presence of Extension Type Alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Under the Nasuni File IQ Alerts section, locate the Presence of Extension Type Alert and click the corresponding Edit button.

  4. Check the Enable Alert box.

  5. (Optional) Check the Enable Webhook box to send alert notifications to a configured webhook endpoint in addition to email.

  6. Use the provided fields to enter the Interval for alert detection, Resend if not resolved after, and optional Footer Alert Text. The following table provides additional parameter information.

Parameter Name

Type

Unit

Description

Min. Value

Max. Value

Interval

Base Setting

Seconds

Alert Interval used for alert detection

300

900

Repeat After

Base Setting

Minutes

Resends an alert notification if not resolved within the selected time interval

5

922000000000000000

Footer Alert Text

Base Setting

Text

Custom text for alert email footer

0 Characters

255 Characters

Webhook Enabled

Base Setting

Toggle

Sends alert notifications to a configured webhook endpoint

-

-

Extensions

Per Entity Setting

File Extensions

List of file extensions to monitor per Volume, separated by semicolons

At least 1 extension

-

Users

Per Entity Setting

User Names

Users to include or exclude from alerting, separated by semicolons (used with Include / Exclude mode)

-

-

Groups

Per Entity Setting

Group Names

Groups to include or exclude from alerting, separated by semicolons (used with Include / Exclude mode)

-

-

Target

Per Entity Setting

Any / Include / Exclude

Determines whether all users/groups are considered, or the list is inclusive or exclusive

-

-

  1. Under the Volume Settings, check the Enabled box for the volumes you want to monitor from the list. You can apply the same settings to all selected volumes or configure each one individually.

  2. Enter the following information:

    - Extensions: Enter the file extensions to monitor for the Volume(s) selected, separated by a semicolon. Each extension can include or omit the leading dot (both .enc and enc are accepted). Composite extensions such as .tar.gz are supported and are treated as distinct from .gz. Wildcards are not supported. Each extension must be an exact match.

    - Target: (Optional) Configure a target filter to control which users and groups are considered for the alert.

    - Users and Groups: Enter user names or group names separated by a semicolon in the respective fields (for example, user1; DOMAIN\user2; DOMAIN\group name). User names and group names are only required when using Include or Exclude mode.

    Alternatively, to bulk edit multiple volumes, follow these steps:

    a. Select the checkbox next to each volume you want to update, or use the Select All checkbox at the top of the list to select all.

    b. Click Edit X Volumes in the top-right corner of the table. A form appears.

    c. Check the Enable box and enter your desired values. Use the table above as a reference.

    d. Click Apply.

  3. Click Save.

Email Notification

An email is sent as soon as the alert firing status changes, and then according to the Repeat After Interval as long as it remains active.

These alerts include the following information:

  • Alert Name: The alert name and the number of instances with status changes are included in the email subject line.

  • Alert notification details:

    • Names of Volumes where matching extension activity was detected.

    • Number of matching events detected.

    • Alert status.

    • When the alert fired (UTC).

    • When the alert resolved (UTC) — empty if unresolved.

  • Alert Description: A brief description of the alert.

  • Shared Configuration: Settings that apply across all monitored Volumes:

    • Interval: Alert Interval used for alert detection.

    • Repeat After: Resends an alert notification if not resolved within the selected time interval.

  • Dashboard Link: A link to the Alerting Inspector dashboard to investigate the matching events in detail, including the extensions detected, the paths, users, groups, and event types involved.

Activity – In Directory Alert

The In Directory Alert detects audit event activity within configured directories on a Volume. Monitoring is recursive — activity in sub-directories of a configured path is also detected. Optional user and group filtering is supported. The detection logic for files being moved or copied checks both the origin and destination directories.

Configuration

To configure the In Directory Alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Under the Nasuni File IQ Alerts section, locate the In Directory Alert and click the corresponding Edit button.

  4. Check the Enable Alert box.

  5. (Optional) Check the Enable Webhook box to send alert notifications to a configured webhook endpoint in addition to email.

  6. Use the provided fields to enter the Interval for alert detection, Resend if not resolved after, and optional Footer Alert Text. The following table provides additional parameter information.

Parameter Name

Type

Unit

Description

Min. Value

Max. Value

Interval

Base Setting

Seconds

Alert Interval used for alert detection

300

900

Repeat After

Base Setting

Minutes

Resends an alert notification if not resolved within the selected time interval

5

922000000000000000

Footer Alert Text

Base Setting

Text

Custom text for alert email footer

0 Characters

255 Characters

Webhook Enabled

Base Setting

Toggle

Sends alert notifications to a configured webhook endpoint

-

-

Directory Paths

Per Entity Setting

Directory Paths

List of directory paths to monitor per Volume, separated by semicolons

At least 1 path

-

Users

Per Entity Setting

User Names

Users to include or exclude from alerting, separated by semicolons (used with Include / Exclude mode)

-

-

Groups

Per Entity Setting

Group Names

Groups to include or exclude from alerting, separated by semicolons (used with Include / Exclude mode)

-

-

Target

Per Entity Setting

Any / Include / Exclude

Determines whether all users/groups are considered, or the list is inclusive or exclusive

-

-

  1. Under the Volume Settings, check the Enabled box for the volumes you want to monitor from the list. You can apply the same settings to all selected volumes or configure each one individually.

  2. Enter the following information:

    - Directory Path: Enter the full directory paths to monitor for that Volume, separated by a semicolon (for example, /folder/reports; /folder/sub-folder). Wildcards are not supported. Each path must be an exact match. Activity in sub-directories of the configured path is also detected.

    - Target: (Optional) Configure a target filter to control which users and groups are considered for the alert.

    - Users and Groups: Enter user names or group names separated by a semicolon in the respective fields (for example, user1; DOMAIN\user2; DOMAIN\group name). User names and group names are only required when using Include or Exclude mode.

    Alternatively, to bulk edit multiple volumes, follow these steps:

    a. Select the checkbox next to each volume you want to update, or use the Select All checkbox at the top of the list to select all.

    b. Click Edit X Volumes in the top-right corner of the table. A form appears.

    c. Check the Enable box and enter your desired values. Use the table above as a reference.

    d. Click Apply.

  3. Click Save.

Email Notification

An email is sent as soon as the alert firing status changes, and then according to the Repeat After Interval as long as it remains active.

These alerts include the following information:

  • Alert Name: The alert name and the number of instances with status changes are included in the email subject line.

  • Alert notification details:

    • Names of Volumes where matching directory activity was detected.

    • Number of matching events detected.

    • Alert status.

    • When the alert fired (UTC).

    • When the alert resolved (UTC) — empty if unresolved.

  • Alert Description: A brief description of the alert.

  • Shared Configuration: Settings that apply across all monitored Volumes:

    • Interval: Alert Interval used for alert detection.

    • Repeat After: Resends an alert notification if not resolved within the selected time interval.

  • Dashboard Link: A link to the Alerting Inspector dashboard to investigate the matching events in detail, including the directories accessed, paths, users, groups, and event types involved.

Volume Processing - Volume File Count Increase Alert

The Volume File Count Increase Alert notifies you when the number of files on a volume grows beyond a set threshold within a defined time period. It helps you quickly identify high file growth that might impact storage performance or capacity.

Configuration

To configure the Volume File Count Increase Alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Under the Nasuni File IQ Alerts section, locate the Volume File Count Increase Alert and click the corresponding Edit button.

  4. Check the Enable Alert box.

  5. (Optional) For customers on File IQ version 10.2+, check the Enable Webhook box to send alert notifications to a configured webhook endpoint in addition to email.

  6. Use the provided fields to enter an Interval, Threshold, Minimum Volume Size, Minimum File Count, Repeat After, and optional Footer Alert Text. The following table provides additional parameter information.

Parameter Name

Unit

Description

Min. Value

Max. Value

Default Value

Interval

Days

Alert Interval used for the alert detection

1

365

7

Threshold

Number of files

Number of files added before the alert fires

0

922000000000000000

1000

Minimum Volume Size

GB

Applies the alert to volume(s) with the specified minimum size

0

922000000000

100

Minimum File Count

Number of files

Applies the alert to volume(s) with the minimum specified file count

0

922000000000000000

1000000

Repeat After

Minutes

Resends an alert notification if not resolved within the selected time interval

5

922000000000000000

1440

Footer Alert Text

Text

Custom text for alert email footer

0 Characters

255 Characters

Empty

  1. For customers on File IQ versions on 10.3.x and earlier, click Save. For customers on version 10.4.1+, continue to the Volume Settings.

  2. Under the Volume Settings, check the Enabled box for the volumes you want to monitor from the list. You can apply the same threshold to all selected volumes or configure each one individually.

    Alternatively, to bulk edit multiple volumes, follow these steps:

    a. Select the checkbox next to each volume you want to update, or use the Select All checkbox at the top of the list to select all.

    b. Click Edit X Volumes in the top-right corner of the table. A compact form appears.

    c. Check the Enable box and enter a Threshold.

    d. Click Apply.

  3. Click Save.

Email Notification

An email is sent as soon as the alert firing status changes, and then according to Repeat After Interval as long as it remains active.

These alerts include the following information:

  • Alert Name: The alert name and the number of instances with status changes are provided in the email subject.

  • Alert notification details: Provided as part of the email body:

    • Nasuni volume names exceeding the event threshold.

    • Number of files.

    • Alert status.

    • When the alert fired (UTC).

    • When the alert was resolved (UTC).

      Note: If unresolved, this field is empty.

  • Alert Description: A brief description of the alert

  • Configuration Summary: Key parameters used in the alert configuration.

    • Interval: Interval used for alert detection.

    • Threshold: Number of files added before the alert fires.

    • Minimum Volume Size: Applies the alert to volumes with the specified size.

    • Minimum File Count: Applies the alert to volumes with the specified minimum number of files.

    • Repeat After: Resends an alert notification if not resolved within the selected time interval.

  • Dashboard Link: A link to the Nasuni File IQ Volume Explorer dashboard.

Volume Processing - Volume Size Increase Alert

The Volume Size Increase Alert notifies you when the total size of a volume grows beyond a specified threshold within a set time frame. It helps you monitor storage usage and detect early signs of high data growth.

Configuration

To configure the Volume Size Increase Alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Under the Nasuni File IQ Alerts section, locate the Volume Size increase Alert and click the corresponding Edit button.

  4. Check the Enable Alert box.

  5. (Optional) For customers on File IQ version 10.2+, check the Enable Webhook box to send alert notifications to a configured webhook endpoint in addition to email.

  6. Use the provided fields to enter an Interval, Threshold, Minimum Volume Size, Minimum File Count, Repeat After, and optional Footer Alert Text. The following table provides additional parameter information.

Parameter Name

Unit

Description

Min. Value

Max. Value

Default Value

Interval

Days

Alert Interval used for the alert detection

1

365

7

Threshold

Percentage

Percentage increase of volume size before alert fires

0

100

5

Minimum Volume Size

GB

Applies the alert to volume(s) with the specified minimum size

0

922000000000

100

Minimum File Count

Number of files

Applies the alert to volume(s) with the minimum specified file count

0

922000000000000000

1000000

Repeat After

Minutes

Resends an alert notification if not resolved within the selected time interval

5

922000000000000000

1440

Footer Alert Text

Text

Custom text for alert email footer

0 Characters

255 Characters

Empty

  1. For customers on File IQ versions on 10.3.x and earlier, click Save. For customers on version 10.4.1+, continue to the Volume Settings.

  2. Under the Volume Settings, check the Enabled box for the volumes you want to monitor from the list. You can apply the same threshold to all selected volumes or configure each one individually.

    Alternatively, to bulk edit multiple volumes, follow these steps:

    a. Select the checkbox next to each volume you want to update, or use the Select All checkbox at the top of the list to select all.

    b. Click Edit X Volumes in the top-right corner of the table. A compact form appears.

    c. Check the Enable box and enter a Threshold.

    d. Click Apply.

  3. Click Save.

Email Notification

An email is sent as soon as the alert firing status changes, and then according to Repeat After Interval as long as it remains active.

These alerts include the following information:

  • Alert Name: The name of the alert and the number of instances with status changes are provided as the email subject.

  • Alert notification details: Provided as part of the email body:

    • Nasuni volume names that exceed the event threshold.

    • Percentage difference.

    • Alert status.

    • When the alert fired (UTC).

    • When the alert resolved (UTC).

    • Note: If unresolved, this field is empty.

  • Alert Description: A brief description of the alert.

  • Configuration Summary: Key parameters used in the alert configuration:

    • Interval: Interval used for alert detection.

    • Threshold: Percentage increase in volume size before the alert fires.

    • Minimum Volume Size: Applies the alert to volumes with the specified minimum size.

    • Minimum File Count: Applies the alert to volumes with the specified minimum number of files.

    • Repeat After: Resends an alert notification if not resolved within the selected time interval.

  • Dashboard Link: A link to the Nasuni File IQ Volume Explorer dashboard.

You can customize the footer that appears at the bottom of the File IQ alert emails. Footer customization is available in two ways:

  • Per alert rule

  • Globally (for all alert rules)

When using both types of footers, the email displays the per-alert footer first, followed by the global footer.

To customize the footer for all alerts, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Use the Alert Footer box to enter your footer text.

  4. Click Save.

To customize the footer for an individual alert, follow these steps:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Scroll down to the Nasuni File IQ Alerts section.

  4. Find the alert for which you want to configure a custom footer and click the corresponding Edit.

  5. Use the Alert Footer Text box to enter your footer text.

  6. Click Save.

Appendix B: Resetting Alerts to the Default Configuration

Resetting an alert restores it to its original default settings. This action disables the alert and removes any custom configurations you’ve applied.

To reset an individual alert:

  1. Navigate to the Nasuni File IQ Edge User Interface using https://FILE_IQ_FQDN:8443, and log in as an Administrator.

  2. Click the Configuration tab and select Alerts Configuration.

  3. Scroll down to the Nasuni File IQ Alerts section.

  4. Find the alert you want to reset, then click the corresponding Reset.

To reset all alerts at once, click Reset All Alerts Configuration.

Appendix C - Known Limitations and Behaviors

IP Subnet Alert: Client IP Not Available for NFS Volumes

The IP Subnet Alert relies on client IP address data present in audit events. For NFS volumes, the client IP address is not included in the audit event data and appears blank in both the alert evaluation and the Alerting Inspector dashboard. As a result, the IP Subnet Alert does not trigger for NFS volume activity.

Note: The IP Subnet Alert is only effective for SMB/CIFS audit events in which client IP data is available.

NFS Read Caching: Reduced Audit Event Visibility for Repeated Reads

Linux caches data from mounted NFS filesystems in the kernel's page cache to improve performance and reduce network latency. Once a file is read, subsequent reads are typically served from the local cache rather than re-fetching data from the NFS server.

This caching behavior is fundamental to the Linux I/O subsystem and cannot be reliably disabled. While some NFS mount options (for example, noac) can reduce metadata caching, there is no reliable way to fully prevent read caching at the filesystem level. As a result, read-after-initial-read patterns might not generate additional NFS audit events, because the data is served from the kernel cache rather than the remote filesystem. Alerts that depend on detecting read events on NFS volumes might not fire for repeated reads of the same file.

Text Input Fields: Semicolons Required as Separators, Commas Not Supported

All text input fields support multiple values using a semicolon (;) as the separator. Commas are not treated as separators because they might appear within valid entries, such as file or directory names.

Note: If a comma is used to separate values, the entire string, including the comma, is stored as a single value and does not match correctly against audit event data.

The following examples show the expected format for each field type:

  • File paths: Enter multiple file path names separated by a semicolon (for example, /folder/report.pdf; /image.png; /folder/sub-folder/data.csv).

  • Users: Enter multiple users separated by a semicolon (for example, user1; user2; user3).

  • Groups: Enter multiple groups separated by a semicolon (for example, group1; group2; group3).

Correct — semicolons as separators:

/finance/sensitive.docx; /hr/payroll.xlsx

Incorrect — commas treated as part of the value:

/finance/sensitive.docx, /hr/payroll.xlsx

This applies to all input fields across all five new alerts: file paths, directory paths, file extensions, user names, group names, and subnets.

Alert State After Configuration Changes

When an alert configuration is saved (for example, by modifying file paths, updating the Target mode, or changing a threshold), the change takes effect in the next evaluation cycle. Until then, the alert state visible in the UI and in email notifications reflects the result of the previous evaluation under the old configuration.

An alert that is currently FIRING might continue to show as firing for up to one full evaluation interval after a configuration change is saved. This is expected behavior and resolves automatically once the next evaluation cycle completes.

Bulk Edit Behavior

As of File IQ version 10.4.1+, the bulk edit capability (using the Edit X Volumes or Edit X Edge Appliances button) is available on all alerts whenever one or more entities (volumes or Edge Appliances) are selected in the entity list. It provides a compact way to apply changes to multiple entities simultaneously without opening each one individually.

Field Population When Entities Are Selected

The behavior of the form fields when using the bulk edit capability depends on how many entities are selected:

Single entity selected: The form is pre-populated with the current saved values for that entity. This makes it easy to review and adjust the settings for a single entity using the compact form view.

Multiple entities selected: All fields in the form are shown blank, regardless of the current values configured for each selected entity. This is intentional because the selected entities might each have different values configured, so no single value can be pre-filled without potentially misrepresenting the state of the others. The one exception is the Enabled checkbox: it is shown checked if one or more of the selected entities are currently enabled.

Multiple entities selected, but only a few fields updated: In the case of selecting multiple entities with the intention to update only some fields, the fields in the form show blank (because of the multiple entities), but upon clicking Apply, only the fields edited by the user are modified across all volumes selected. This selective editing helps modify only the intended fields, without altering those already configured for the alert.

Alert email notifications for the match-based alerts include a link to the Alerting Inspector dashboard. This link includes a time range parameter that pre-scopes the dashboard to the time window associated with the events triggering the alert; this helps frame the inspection around the time the alert fired, even if the dashboard is visualized at a later stage.

The time range can be adjusted at any time using the time picker in the top-right corner after opening the dashboard.

Investigating Alerts with the Alerting Inspector Dashboard

For the four match-based alerts (Honeypot Files, IP Subnet, Presence of Extension Type, and In Directory), detailed investigation context is available through the Alerting Inspector dashboard in Nasuni File IQ.

For more information on the Alerting Inspector Dashboard, see the Alerting Inspector Dashboard documentation.