21-15
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 21 Rules
Constructing a Rule
Action
Identifies the action that MARS will
take when the rule is fired. Actions
are user-defined alerts that include
an action name and description,
which also doubles at the message
text provided in the alert. Each
action can combine alert techniques,
such as email and syslog. Each alert
technique can have multiple values.
For example, an action can generate
two emails, a page, and a SNMP
trap. Each rule can have multiple
such actions. Alerts can be
constructed using one or more of the
following techniques:
Note
You will see the column
Action/Operation. In this
case, you can select either
one of the following actions
or one of the operators.
•
NONE
—(Default) This action
states that no further action will
be taken. When NONE value is
selected, the firing of the rule
causes an event record to be
created and stored in MARS.
Regardless of the selected action,
this record is always created.
•
—Identifies the list of
administrators to whom an alert
should be sent. An e-mail address
must be defined for the selected
administrators.
•
Syslog
—Identifies the list of
hosts to whom an alert should be
sent. You can select any number
of devices to which you want a
syslog message sent.
•
Page
—Identifies the list of
administrators to whom an alert
should be sent. The message
format is text. A pager number
must be defined for the selected
administrators.
•
SNMP
—Lists the hosts to which
a Simple Network Management
Protocol (SNMP) alert can be
sent.
•
SMS
—List of users to receive
notification by Short Message
Service (SMS). The message can
be up to 160 characters. An SMS
number must be ten numbers and
a domain name, for example,
[email protected].
•
Distributed Threat Mitigation
(DTM)
— Lists the Cisco IOS
Intrusion Prevention System
(IPS) devices to which an IPS
alert action can be sent (alarm,
alarm and drop, or alarm and reset
if it is a TCP session.) See the
Technology Preview: Configuring
Distributed Threat Mitigation
with Intrusion Prevention System
in Cisco Security MARS, page 1
document for DTM configuration
information.
Table 21-1
Rule Fields and Arguments
Rule Field
Field Description and Arguments
Argument Descriptions
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...