I am trying to send an email alert when an IPS log entry targets one of the ports I have open WAN>LAN.

I can create a report for that (using a query on the destination port).

I am not sure how to create an alert rule for it. There is an IPSLogEvent class for Alert rules, but there is no port number available. The only things resembling a port number are:
dportIcode int The dportIcode
sportItype int The sportItype

from https://wiki.untangle.com/index.php/...entionLogEvent

I don't understand the description and I am surprised that the available fields of the IPSLogEvent alert rules seem so different from the fields in the events themselves.

Any idea how to do this?