That's true about limited alerts. Assuming you have the license and IPS/IDS and AMP enabled you can send security events to your own syslog server or a cloud one like papertrailapp.com. That is what I do-

From there you can trigger email, SMS alerts or hook into Slack, Glip, etc.
- Ex community all-star (⌐⊙_⊙)