Set up alerts that matter: email, webhooks and less noise
Configure NetBlade alerts by email or webhook: set up a mail server, choose topics, devices and timing, and keep the noise low enough to read.
An alert is only useful if you still read it next month. NetBlade lets you decide what you are told about, for which devices, on which site, to whom and when, and it deliberately keeps the list of topics short. This article sets up the sending side once, then builds a small set of alerts that catch what matters without burying you.
Before you start
- The agent running, with an active subscription or trial, and a user signed in to Windows on the NetBlade PC (Get started).
- For email: the SMTP server name, port, encryption and an account allowed to send. For a webhook: the URL your chat or automation tool gives you.
- At least one site with devices, and ideally PCs read in depth.
1. Understand when alerts go out
Alerts are sent by the agent, which runs while you are signed in to Windows. If the PC is off or nobody is signed in, alerts wait and go out when it is back. Two more rules:
- A new alert starts from now. What happened before you created it is not sent.
- «Defences switched off» fires only on real transitions: when a read actually sees antivirus, firewall or BitLocker go from on to off, never for “we could not tell”.
Every email says it plainly in its footer: it reports what happened, and a gap means nobody looked.
2. Add a mail server or a webhook
Servers are set up once, in Settings; the Alerts page and scheduled reports then use them.
- Open Settings, section Mail servers and webhooks, and press Add a server.
- Choose the Kind: Email or Webhook, and give it a Name.
- For Email, fill in:
- SMTP server and Port;
- Encryption: Automatic, STARTTLS, TLS from the start (465) or None;
- User and Password;
- From (leave empty to use the user);
- To: one address, or several separated by a comma.
- For Webhook, fill in the URL. NetBlade posts a JSON document there. The same sentence is carried under
text,contentandmessage, so Slack, Discord and most automation platforms show something without any transformation; the individual items are underitems. - Press Add, then Send a test on the new server’s row. Check that the message arrives.
The password is encrypted with Windows DPAPI for your account, like every other secret in NetBlade.
Tip: General SMTP advice: port 587 usually goes with STARTTLS and port 465 with TLS from the start. Many mail providers require SMTP authentication to be enabled for the mailbox, or an app-specific password, before an application can send. A dedicated mailbox for alerts makes filtering and auditing easier.
Warning: Never rely on a server you have not tested. The app says it too: a channel nobody has proved looks exactly like one that works.
3. Know the seven topics
| Topic | What triggers it |
|---|---|
| New devices | A device nobody had ever seen answered on a network you watch |
| Devices that stopped answering | Something that used to answer does not any more |
| Ports newly open | A port opened on a device that already existed |
| Watched targets going down | A target on the Monitor page stopped answering |
| Defences switched off | Antivirus, firewall or BitLocker went from on to off on a machine that was read |
| Software changes | A program appeared, went away or changed version on a machine that was read |
| New things to fix | A new entry on the To fix list, with a threshold |
New things to fix is the only topic with a threshold: Only what is being exploited, That, and the likely ones, or Everything found. The first read of an ordinary office produces a hundred findings, and a channel that forwards all of them is a channel somebody mutes.
4. Create an alert
- In the menu open Alerts and press New alert.
- In What, choose the topic. For New things to fix, choose the threshold in Which.
- In Which devices, tick the device types you care about, for example Camera and NVR. No tick means all.
- In Where, choose the site.
- In To, choose the server that will send it.
- In When, choose Tell me at once or In the daily summary.
- Press Save. The table shows ON, WHAT, WHICH DEVICES, WHERE, TO and WHEN; use Edit to change a rule.
Alerts set to the daily summary arrive together once a day. Set the hour for each server under Daily summary on the same page. If the PC is off at that hour, the summary goes as soon as it is back.
5. A starter set that stays quiet
For a typical small office, per site:
| Alert | When |
|---|---|
| New things to fix, Only what is being exploited | Tell me at once |
| Defences switched off, all device types | Tell me at once |
| Watched targets going down | Tell me at once |
| Devices that stopped answering, only servers, NAS, cameras, NVR | Tell me at once |
| New devices | In the daily summary |
| Ports newly open | In the daily summary |
| Software changes | In the daily summary |
The logic: at once only for what needs action today, everything else in one daily email you read with your coffee.
Tip: «Devices that stopped answering» for all types is the noisiest alert you can create: every laptop that goes home counts. Limit it with Which devices to equipment that should always be on.
6. Watch what must always answer
Alerts about “stopped answering” depend on scans. For the few things that must never be down (the internet line, the file server, the customer’s web shop), add a Monitor target:
- Open Monitor.
- Type the Address or name, choose How (Ping, TCP port or HTTP) and, if needed, the Port.
- Press Watch it.
Targets are checked about once a minute while you are signed in to Windows. An HTTP target counts as up when the response is below code 500. Pair it with the Watched targets going down alert.
7. Silence one device without losing it
A test machine that goes up and down all day does not deserve an alert every time.
- On its card, press Edit… and turn on Silent («No notifications about this one»).
- For several devices at once, use Select on the device list, then Mass edit, field Alerts muted.
A muted device stays in the table and the timeline; it just sends no alerts.
8. Windows notifications
Besides alerts, the agent can show Windows notifications for a new device, a watched target down or back, and new findings. Turn them on or off in Settings, Behaviour, Notifications.
Check that it worked
- Each server shows «Last attempt …, sent» after Send a test.
- What was sent, on the Alerts page, lists messages actually delivered, and failures with their reason.
- Send what is owed forces pending messages out now; «Nothing to send: every rule is up to date with what has happened» means you are current.
If something goes wrong
- «Sending alerts needs a mail server or a webhook first». Add one in Settings, Mail servers and webhooks.
- The test fails. Check server, port and encryption together (a mismatch between port and encryption is the usual culprit), then the user and password, then whether the provider allows SMTP from applications.
- «Not an http or https address». The webhook URL must start with
http://orhttps://. - «No recipient». The email server needs at least one address in To.
- Alerts arrive hours late. The PC was off or nobody was signed in. Alerts go out when the agent runs again.
- No alert for something that happened last week. Alerts start from the moment you create them.
- No «Defences switched off» although antivirus is off. The alert fires on a change seen by a read. If the machine was never read with the defence on, there was no transition to report; the finding is on To fix.
Next
Turn the same data into something you can hand over: Reports for your clients.
← All how-to guides Feature guide → The product: NetBlade Windows →