Notification Settings

Overview

Notification Settings lets each user control how they receive notifications inside Logsign USO. For every notification type, you can choose whether it appears in the Notification Center, as a popup, by e-mail, or by SMS. These preferences are personal: each user configures their own settings, and they do not affect what other users see.

The list of notification types you can configure depends on your license and role:

  • If the Incident module is licensed, incident and task related events are available, including Incident Assign, Incident Close, Add Contributors, Remove Contributors, Priority Update, Task Assign, Task Reassign, Task Update, Task Status Update, Task Remove, Decision Assign, Decision Reassign, Decision Update, Decision Answer, Decision Remove, and Action Rule Failed.
  • Administrators and other non standard user accounts also see system health check notifications, such as Index Service Status, Syslog Service Status, Disk Check, Collection Check, License Expire Check, and System Update. If Leaf mode is enabled, Leaf Center Status and Leaf Status are included as well.

Accessing Notification Settings

  1. Click the notification (bell) icon in the top right corner of the header.
  2. Stay on the Event tab of the notifications panel. Notification Settings is only available from this tab, not from the System tab.
  3. Click Notification Settings at the bottom right of the panel.

Using Notification Settings

  • Disable Notifications: a master switch at the top of the window. Turning it on suppresses every notification type at once and hides the table below it.
  • Disable All / Enable All: links that turn every channel off or on for every notification type in one click. Use Save to apply the change.
  • Per row channels: each notification type has its own checkmarks for Notification Center, Popup, E-Mail, and Sms. Click a checkmark to toggle it. Popup requires Notification Center to be enabled for that row: turning Popup on automatically turns Notification Center on as well, and turning Notification Center off automatically turns Popup off. E-Mail and Sms are independent and are not linked to the other columns.

Click Save once you are done to apply your changes.

Notes

  • Settings are stored per user account. If a specific colleague should stop receiving certain notifications, that colleague needs to open Notification Settings from their own account.
  • Incident and task related rows only appear when the Incident module is licensed on the instance.
  • You never receive a notification for your own actions. If you assign an incident to yourself, close an incident yourself, or update your own task, no notification is generated for that action.
  • The E-Mail and Sms columns only deliver messages if a default e-mail or SMS response integration is configured on the instance, under Settings, Response Integrations, with "default" enabled for that integration type. Notification Center and Popup do not depend on this.

What Each Notification Type Means

Every row in the Tasks table corresponds to a specific event in the Incident, Task, and Decision workflow. The table below explains when each one fires and who receives it.

Notification TypeFires whenSent to
Incident AssignAn incident is assigned to a userThe newly assigned incident owner
Incident CloseAn incident is closedEvery contributor on the incident, except the person who closed it
Add ContributorsA user is added as a contributor on an incidentThe user who was just added
Remove ContributorsA user is removed from an incident's contributor listThe user who was removed
Priority UpdateAn incident's priority is changedThe incident owner and every contributor
Task AssignA task is created, or an existing task's owner is changedThe new task owner
Task ReassignAn existing task's owner is changed to someone elseThe previous task owner
Task UpdateA task's description is editedThe task owner
Task Status UpdateA task's status changes (Completed, Can't Complete, or Incomplete)The task's creator
Task RemoveA task is deletedThe task's owner
Decision AssignA decision is created, or an existing decision's owner is changedThe new decision owner
Decision ReassignAn existing decision's owner is changed to someone elseThe previous decision owner
Decision UpdateA decision's description is editedThe decision owner
Decision AnswerA decision is answered by its ownerThe decision's creator
Decision RemoveA decision is deletedThe decision's owner
Action Rule FailedAn automated action rule, a playbook action tied to an incident, fails to runEvery user who has this notification type enabled, not just one person

A few points are worth calling out because they are not obvious from the interface:

  • Task Assign fires twice on reassignment. When a task's owner is changed, the new owner gets a Task Assign notification and the previous owner gets a separate Task Reassign notification. The same pattern applies to Decision Assign and Decision Reassign.
  • Task Status Update goes to the creator, not the owner. If Alice creates a task and assigns it to Bob, Bob is the one who marks it complete, and Alice, the creator, gets notified that the status changed, not Bob.
  • Decision Answer goes to the creator, not the owner. The owner is the one who answers the decision. The notification tells the decision's creator that it has been answered.
  • Action Rule Failed is a broadcast, not a targeted notification. It is not tied to a specific incident owner or contributor. It goes out to every user who has this row enabled in their own Notification Settings, which is why it is enabled by default (Notification Center only) even before a user has ever opened this screen.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.