21-14
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 21 Rules
Constructing a Rule
Time Range
Identifies the period of time over
which the count value is augmented.
For rules that have a Count value
greater than one, the Time Range
value determines how long the
period should be before the count
value is reset. For example, you can
assume that if no more than three
login attempts have occurred over a
10-minute period that counter can be
reset.
Usage Guideline: The Time Range
value combined with the Count value
can affect the operation of your
MARS. Each time an event is captured
that satisfied a unique instance of an
inspection rule, a monitoring session
is constructed to track possible future
occurrences until either the Count
value is reached or the time period
expires.
Table 21-1
Rule Fields and Arguments
Rule Field
Field Description and Arguments
Argument Descriptions