> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Notification Rule for Investigations

|                       |           |              |         |             |
| --------------------- | --------- | ------------ | ------- | ----------- |
| **Role Availability** | Read-Only | Investigator | Analyst | **Manager** |

USM Anywhere creates a default notification rule that sends an email notification when there is a change to an investigation.

This is a system rule, and the allowed actions are Enable, Disable, and Edit. If you try to delete it, the rule is restored during the next system update. Go to **Settings > Rules** to view this notification rule.

<Note>
  **Note:** By default, this rule is disabled.
</Note>

<Note>
  **Note:** These rules use the *event\_severity* field with the values low, medium, high, and critical, and the *event\_action* field with the values created, deleted, and updated.
</Note>

**To enable the notification rule for investigations**

1. Go to **Settings > Rules**.

2. Locate the USM Anywhere Investigations Notification rule and click the <img src="https://mintcdn.com/levelblue-5324744e/9HhQ6wK11ydctaHc/images/usm-anywhere/toggle-off-new.svg?fit=max&auto=format&n=9HhQ6wK11ydctaHc&q=85&s=bed00ce5e148a8148e763548ae6c8199" className="inline" width="32" height="16" data-path="images/usm-anywhere/toggle-off-new.svg" /> icon. This turns the <img src="https://mintcdn.com/levelblue-5324744e/9HhQ6wK11ydctaHc/images/usm-anywhere/toggle-on-new.svg?fit=max&auto=format&n=9HhQ6wK11ydctaHc&q=85&s=b0ecf1b6c804d5cf5eac9ea50b41480d" className="inline" width="32" height="16" data-path="images/usm-anywhere/toggle-on-new.svg" /> icon green. To disable the rule, toggle the icon to its original status.

   <Frame>
     <img src="https://mintcdn.com/levelblue-5324744e/JttNYaikKbN1las-/images/usm-anywhere/notificationrule.webp?fit=max&auto=format&n=JttNYaikKbN1las-&q=85&s=25bb61261b187b69003600d008c2de0b" alt="" width="2184" height="362" data-path="images/usm-anywhere/notificationrule.webp" />
   </Frame>

3. Click an investigation to display its details.

**To edit the notification rule for investigations**

1. Go to **Settings > Rules**.

2. Locate the USM Anywhere Investigations Notification rule and click the <img src="https://mintcdn.com/levelblue-5324744e/2zcwC17_yhGqZqy4/images/usm-anywhere/pencil-new.svg?fit=max&auto=format&n=2zcwC17_yhGqZqy4&q=85&s=3fe3fa0ee6ce2b44857bf81d5ab975d9" className="inline" width="24" height="24" data-path="images/usm-anywhere/pencil-new.svg" /> icon.

   <Frame>
     <img src="https://mintcdn.com/levelblue-5324744e/fC92IJE7ax567GE5/images/usm-anywhere/user-guide/editnotificationrule_new.webp?fit=max&auto=format&n=fC92IJE7ax567GE5&q=85&s=f516a2c70e20d1783de5e24179d61608" alt="" width="818" height="622" data-path="images/usm-anywhere/user-guide/editnotificationrule_new.webp" />
   </Frame>

3. Make the changes as needed and click **Save Rule**. See [Notification Rules from the Orchestration Rules Page](https://cybersecurity.att.com/documentation/usm-anywhere/user-guide/rules-management/notification-rules) for more information on editing notification rules.

<Note>
  **Note:** The destination email field includes the emails of the users created in the environment as the role of Managers. See [Role-Based Access Control (RBAC) in USM Anywhere](https://cybersecurity.att.com/documentation/usm-anywhere/user-guide/user-management/rbac) for more information.
</Note>
