Skip to main content

Notifications

Anzenna sends notifications when detections find new security events or when investigations are completed or updated.

  • Detection notifications are event-centric — they tell you how many new events have occurred since the last notification, not the total count.

  • Investigation notifications are status-driven — they fire when an investigation completes or its status changes, delivering the outcome, headline, and a link to the full report.

Settings > Notifications page overview

Delivery Channels

Anzenna supports five delivery channels. Each has its own setup guide:

  • Email

    — Individual or digest emails to your security team

  • Webhooks

    — JSON payloads to Tines, N8N, or any HTTP endpoint for SOAR automation

  • Slack

    — Messages to Slack channels via incoming webhooks

  • Freshservice

    — Tickets opened in your Freshservice instance for detections

  • Microsoft Sentinel

    — Detection records pushed into your Log Analytics workspace


Configuration Levels

Notifications are configured at two levels:

  • Global defaults — configured in Settings > Notifications. These apply to all detections and investigations unless overridden.

  • Per-source overrides — each detection or investigation can use its own independent notification configuration, overriding the global defaults.

Per-Detection Overrides

  1. Navigate to the Detections page

  2. Click on a detection to open the detail drawer

  3. Open the Notifications tab

  4. Toggle Use custom notification configuration

Detection notifications tab inheriting global settings

When the toggle is off, the detection inherits all global settings. Any changes to global config automatically apply.

When the toggle is on, the detection uses its own independent configuration. You can customize:

  • Email enable/disable and recipient list
  • Webhook enable/disable and provider selection

  • Frequency mode and batch window
  • Max events per notification
  • Silencing options (permanent disable, snooze)

Detection notifications tab with custom configuration enabled

Investigation overrides follow the same pattern — open an investigation, go to the Notifications tab, and toggle custom configuration.

Snoozing switches to custom config

If you snooze a detection or investigation that's using global config, the system automatically switches it to custom configuration (copying your current global settings as a starting point). After the snooze expires, it stays on custom config — toggle Use custom notification configuration off manually to re-inherit global settings.


Frequency Modes

The frequency mode controls when notifications are sent. It can be set at the global level or overridden per-detection.

  • Email — A single digest email is sent periodically covering all detections and investigations with updates. The batch window is configurable (default: 60 minutes).

  • Webhook — Fires immediately per-source regardless of the batch window. Automation tools need real-time events for SOAR workflows, so webhooks are never batched.

The system automatically deduplicates — if nothing has changed since the last notification, no notification is sent.

Immediate

Both email and webhook fire on every recalculation where there's something new to report. Use this when you need real-time email alerts for specific detections or investigations.

Threshold

Notifications fire only when the event count exceeds a configured value. Once the threshold is crossed and a notification fires, the count must increase again to trigger another notification. Use this for alerting only on significant accumulations.


Silencing Options

Silencing lets you temporarily or permanently suppress notifications:

  • Permanently disable — stops all notifications until you manually re-enable them

  • Snooze — suppresses notifications for a set duration (1 hour, 24 hours, or 7 days)

Silencing options

Need help? Contact

Anzenna Support

for assistance.