21-17
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 21 Rules
Working with System and User Inspection Rules
Working with System and User Inspection Rules
Navigate to the
Inspection Rules
page by clicking the
Rules
tab.
You can perform the following actions with Inspection Rules:
•
Change the Source IP, Destination IP and Device fields of a System Inspection rule
•
Duplicate any Inspection Rule then edit the fields to make a new User Inspection Rule
•
Build a new User Inspection Rule with the Rule wizard
•
Edit any field of a User Inspection Rule
•
Make any rule active or inactive
•
Edit, delete, or add, a Rule Group
Note
When you add or edit a rule, you must click
Activate
to enable the changes.
Note
Upgrade the MARS software regularly to obtain new and updated System Inspection rules. For more
information, see the
Install and Setup Guide for Cisco Security Monitoring, Analysis, and Response
System
. To view a list of System Inspection rules, see
Appendix D, “System Rules and Reports.”
Change Rule Status—Active and Inactive
The CS-MARS correlation engine continuously tests only active rule criteria against incoming events to
identify incidents. Inactive rules do not consume resources used for realtime operations.
Note
A rule cannot be deleted, it can be made active or inactive.
To change the status of a rule, follow these steps:
Step 1
Navigate to the
Rules
>
Inspection Rules
page.
Step 2
Select the checkbox of the rule (or rules) to change.
Step 3
Click
Change Status
.
The selected rules are made inactive if active, and active if inactive and displayed on a different page.
Step 4
To display inactive rules, select
Inactive
from the View dropdown list. To display active rules, select
Active
.
Duplicate a Rule
Duplicating a rule creates a new rule that is a copy of an existing system or user inspection rule. You
can edit all of the fields of a duplicate rule, but only the Source IP, Destination IP, and Device fields of
a system inspection rule. The original rule is left unchanged after duplication.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...