What gets generate by the alert depends on how the alert is configured. Alerts don't generate any logs other than NT event logs unless you have a custom script that is executed by the alert (configuration option). Anything that violates the rule as you've defined it should kick the alert. Jim Harrison MCP(NT4, W2K), A+, Network+, PCG http://isaserver.org/authors/harrison/ Read the books! ----- Original Message ----- From: "Nathan Simpson" <nathansimpson@xxxxxxxxxxxxxxx> To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx> Sent: Tuesday, May 21, 2002 5:04 PM Subject: [isalist] Re: Alerts http://www.ISAserver.org Jim, I have the SMTP filter installed on its own box which communicates with the ISA server which has its own box. The filters work as does the relay in both directions. I know how to configure the alerts and those are working too. What I want to know is, is the alert only kicked off with a command rule or do attachment and keyword rules also initiate the alert? And also, are there logs when an alert is created or can they only be viewed by the ISA management console or NT event viewer or email? Nathan ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub')