Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 435

Security mars local controller
Table of Contents

Advertisement

Chapter 21
Rules
Table 21-1
Rule Field
Action
78-17020-01
Rule Fields and Arguments
Field Description and Arguments
Identifies the action that MARS will
take when the rule is fired. Actions
are user-defined alerts that include
an action name and description,
which also doubles at the message
text provided in the alert. Each
action can combine alert techniques,
such as email and syslog. Each alert
technique can have multiple values.
For example, an action can generate
two emails, a page, and a SNMP
trap. Each rule can have multiple
such actions. Alerts can be
constructed using one or more of the
following techniques:
You will see the column
Note
Action/Operation. In this
case, you can select either
one of the following actions
or one of the operators.
Argument Descriptions
NONE—(Default) This action
states that no further action will
be taken. When NONE value is
selected, the firing of the rule
causes an event record to be
created and stored in MARS.
Regardless of the selected action,
this record is always created.
Email—Identifies the list of
administrators to whom an alert
should be sent. An e-mail address
must be defined for the selected
administrators.
Syslog—Identifies the list of
hosts to whom an alert should be
sent. You can select any number
of devices to which you want a
syslog message sent.
Page—Identifies the list of
administrators to whom an alert
should be sent. The message
format is text. A pager number
must be defined for the selected
administrators.
SNMP—Lists the hosts to which
a Simple Network Management
Protocol (SNMP) alert can be
sent.
SMS—List of users to receive
notification by Short Message
Service (SMS). The message can
be up to 160 characters. An SMS
number must be ten numbers and
a domain name, for example,
1234567890@provider.com.
Distributed Threat Mitigation
(DTM)— Lists the Cisco IOS
Intrusion Prevention System
(IPS) devices to which an IPS
alert action can be sent (alarm,
alarm and drop, or alarm and reset
if it is a TCP session.) See the
Technology Preview: Configuring
Distributed Threat Mitigation
with Intrusion Prevention System
in Cisco Security MARS, page 1
document for DTM configuration
information.
User Guide for Cisco Security MARS Local Controller
Constructing a Rule
21-15

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents