Skip to main content

Machine Anomaly Alerts

Lacework generates machine-based alerts when there are machine-related vulnerabilities detected. You can define alert rules to trigger alerts when machine-related vulnerabilities are found. See Alert Rules.

Alert List

The following table lists all the machine-based alerts.

Alert NameAlert TypeAlert SubcategoryConnection
Bad external client DNSNewExternalClientBadDnsMachineDomain -> Machine
Bad external client IP addressNewExternalClientBadIpMachineIP -> Machine
New external client DNSNewExternalClientDnsMachineIP -> Machine
New external client IP addressNewExternalClientIpMachineIP -> Machine
Bad external hostNewExternalServerBadDnsMachineMachine -> Domain
Bad external server IP addressNewExternalServerBadIpMachineMachine -> IP
Outbound connection to new domain from host

Note:
Legacy name: New external host
NewExternalServerDnsMachineMachine -> Domain
Outbound connection to new domain from application

Note:
Legacy name: New external host
NewExternalServerDnsMachine
Outbound connection to a new external IP address from host

Note:
Legacy name: New external server IP address
NewExternalServerIpMachineMachine -> IP
Outbound connection to a new external IP address from application

Note:
Legacy name: New external server IP address
NewExternalServerIpMachine

Suppress an Alert

Suppressing specific machine-related alerts reduces the number of alerts and allows you to focus on the assets that are most important to you. For details, see Suppress Behavior Anomaly Alerts.