WiscIT - Default Email Monitoring Behavior
General steps for processing mail
When a new email arrives to a WiscIT-monitored email account, the following steps happen:
-
WisIT checks the account's Inbox for mail.
-
It checks each mesage against the rules for the account in the order defined for the rules.
-
When a rule is found where the message meets the criteria of the rule, it processes that rule for the message. It does not process other rules.
-
If the message is processed successfully, WiscIT moves the message in the servic account to the Ivanti Processed folder. If it could not process the message, WiscIT moves the message to the Ivanti Errors folder.
Standard rules for mail accounts
There are two abstract "categories" of accounts in WiscIT: accounts that can be used as a from address in WiscIT, and accounts that cannot be used as a from address in WiscIT.
Standard rules for mail accounts that are valid from addresses in WiscIT
At the time of writing, valid from addresses in WiscIT are:
-
- wiscit@doit.wisc.edu
- help@doit.wisc.edu
- support@doit.wisc.edu
- cybersecurity@cio.wisc.edu
Update existing Incident and Service Request rules
Accounts that are valid from addresses in WiscIT have update existing incident and service request rules; if a matching CMI is found in the email, WiscIT will link the email to the incident or service request, and update the incident or service request status to "Needs Attention".
Custom rules
Some of these accounts have rules configured to e.g. create an incident with a specific classification.
Default rule
The default rule for these accounts is to create an email with no parent incident or serice request; the team that is responsible for monitoring these emails either:
-
-
Resolve the email without creating a parent.
-
Create a parent incident through which to track the interaction.
-
Standard rules for mail accounts that are NOT valid from addresses in WiscIT
Update existing Incident and Service Request rules
Accounts that are not valid from addresses in WiscIT do NOT have update existing object rules.
Custom rules
Some of these accounts have rules configured to e.g. create an incident with a specific classification.
Default rule
The default rule for these accounts is to create an incident with:
-
-
Service: The service correlated with the account.
-
Classificaiton: Service Inquiry
-
OwnerTeam: The team that owns the Service in the CMDB.
-