> Source: [sk101108](https://support.checkpoint.com/results/sk/sk101108)

# sk101108 - Trying to create mail reaction based on specific event severity, but receive Alerts with all severities

| Property | Value |
|----------|-------|
| Solution ID | sk101108 |
| Date Created | 2014-06-16 |
| Last Modified | 2020-07-27 |
| Technical Level | General |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R82.20 |
| OS | Windows, Gaia |

## Symptoms

- Trying to create mail reaction based on specific event severity, but receive Alerts with all severities.

## Cause

Misconfiguration of mail alerts based on severity.

The "Severity" button above the "Automatic Reactions" button is used to set the severity of the whole event and not for the Mail Alerts filter.

## Solution

In order to configure SmartEvent to send alerts by mail for events, based on severity, proceed as follows:

1. Connect to SmartEvent GUI.
2. Go to Policy tab.
3. Choose the desired event.
4. Right-click on the event \> Save as + Add name (Create a user defined event).
5. Right-click on 'new user defined event \> Properties \> Filter tab \> Show more fields \> Existing fields\> Severity \> OK'.
6. Double-click 'Severity filter \> Add \> in the Add value - Choose severity between 0-4 (0- Informational, 4 - Critical).
7. Add the Severity field to the filters.
8. Choose 'match - All conditions \> OK'.
9. In the user defined event you created, 'Set Automatic reaction \> Choose Mail \> Configure the mail categories \> Save \> OK'.
10. Save and install the events policy.

**Related Solution(s):**

[sk93970: ATRG: SmartEvent](http://supportcontent.checkpoint.com/solutions?id=sk93970)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
