How can we help?

How to set up and configure the New Network Device Discovered alert

Follow

A New Network Device Discovered alert can notify Auvik users when Auvik identifies a new network device.

What the alert monitors

When enabled with its default configuration, the alert can notify you when Auvik discovers supported network devices such as:

  • Firewalls
  • Routers
  • Layer 3 and Layer 2 switches
  • Switch stacks
  • Packet processors
  • Controllers
  • Access points

The newly discovered device must be identified as one of the supported device types before the alert can trigger.

What the alert does not monitor by default

The alert is focused on network devices that Auvik can identify. It does not trigger by default for generic devices.

As a result, devices such as printers, workstations, laptops, phones, and other endpoints may not generate this alert unless they are included through customized entity settings and meet the applicable discovery criteria.

If you need to identify unknown endpoints, use the appropriate endpoint-management, network-access-control, 802.1X, or switch-port-security tools for your environment. These controls are outside the Auvik alert and must be configured by the appropriate network or security administrator.

Important alert behavior

  • The alert is disabled by default.
  • Devices discovered before the alert was enabled do not generate a new discovery alert.
  • The alert does not notify you when a device that was already discovered goes offline and later comes back online.
  • Auvik may take approximately five to ten minutes to consolidate newly discovered IP addresses with existing device records before displaying the alert.
  • If a device is deleted from Auvik, its alert history is also removed.
  • The alert is not intended to function as a complete audit record unless it is used with a PSA or other workflow that retains the notifications.
  • The alert does not support replication. If different alert behavior is required, review the available entity and site-scoping options.

How to enable the New Network Device Discovered alert

  1. From you Auvik Dashboard, click Manage Alerts from the side navigation bar.ManageAlertsNav.png
  2. Search for New Network Device Discovered.C6ECD58E-E62D-4E68-AC6D-3F220F644ABF.png
  3. The New Network Device Discovered alert will appear in the Manage Alerts search list. Click the Checkbox beside Informational.3E3FEB90-57BC-4053-BAD7-65EB18752959_4_5005_c.jpeg
  4. Click Enable.E9F28D58-1B9A-420D-8FFF-38B07B905471_1_105_c.jpeg

When Auvik discovers a device on a new IP, Auvik will process it and all new IPs to consolidate the IPs under the devices to which the IPs belong. After the internal process is complete, and if the device is one of the device types covered under the alert, Auvik will report and display the alert.

 

Optional: How to edit the New Network Device Discovered alert

Setting up the alert for all devices may cause excessive,“noisy” alerting. Auvik’s current settings do not allow replication of this alert.

  1. Alert Name and Alert Description can be customized as desired.
  2. Under Describe the Alert, click the pull down button to select the Alert Severity and select the desired severity.2C309AFB-49FF-40A2-9467-4C4547237BB5.png
  3. Under Select Entities, all the billable devices and access points will be selected by default but this can be altered as desired. You can find the information on how to Select Entities here.
  4. The No Clear Condition - Clear by Dismissing alert does not have an automated clear condition in the set up. It needs to be manually cleared from Auvik or by integration with a ticketing system when the alert is cleared.

Recommended operational practices

To make new-device alerts easier to investigate:

  • Maintain an inventory of approved network devices.
  • Use consistent device names that identify the site, location, or function.
  • Keep device types and other available metadata accurate.
  • Review new discovery alerts promptly.
  • Confirm whether the device is expected before adding it to the approved inventory.
  • Review the device record after discovery to confirm its classification and monitoring status.
  • Use separate network-access-control or endpoint-security processes when the goal is to identify every endpoint on a switch port.

Clearing the alert

The default No Clear Condition – Clear by Dismissing setting does not automatically clear the alert.

To close the alert, dismiss it manually or use an integration or ticketing workflow that manages the alert lifecycle.

Related articles

Was this article helpful?
1 out of 2 found this helpful
Have more questions? Submit a request