22-9
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 22 Sending Alerts and Incident Notifications
Configure a Rule to Send an Alert Action
For Syslog and SNMP, the
Select
(device) dialog box appears, as shown in
Figure 22-5
.
Figure 22-5
Device Selection Page
For Distributed Threat Management notification, the Select (IOS-IPS Devices) dialog appears (not
shown).
Tip
If you do not know the group to which a user or device belongs, select
All
from the dropdown list to
view all users or devices.
Step 7
Click the check box next to the users or device you want to receive the notification, then click <<
Add
.
Your selections appear in the left-hand area. To remove items, Ctrl+click the items in the left-hand area,
then click
Remove
. The items are then deleted from the left-hand area.
Step 8
If you are not adding a user, skip to Step
9
. To add a new user, do the following substeps:
a.
Click
Add.
The User Configuration page appears in a separate window, as shown in
Figure 22-6
.
b.
Enter the User Configuration information then click
Submit
.
You are returned to the
Select Recipient Dialog Box
.
For reference on user configuration fields, see the section,
“Create a New User—Role, Identity,
Password, and Notification Information”
c.
Add the new user to the recipient list as described in Step
7
.
Step 9
Click
Submit
.
You are returned to the
Alert Recipients Window
.
Step 10
Repeat Step
6
through Step
9
until you have assigned recipients to all the notification types you have
selected.
Step 11
Click
Submit
.