Working With System And User Inspection Rules; Change Rule Status-Active And Inactive; Duplicate A Rule - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Chapter 21
Rules

Working with System and User Inspection Rules

Navigate to the Inspection Rules page by clicking the Rules tab.
You can perform the following actions with Inspection Rules:
When you add or edit a rule, you must click Activate to enable the changes.
Note
Note
Upgrade the MARS software regularly to obtain new and updated System Inspection rules. For more
information, see the Install and Setup Guide for Cisco Security Monitoring, Analysis, and Response
System. To view a list of System Inspection rules, see
Change Rule Status—Active and Inactive
The CS-MARS correlation engine continuously tests only active rule criteria against incoming events to
identify incidents. Inactive rules do not consume resources used for realtime operations.
A rule cannot be deleted, it can be made active or inactive.
Note
To change the status of a rule, follow these steps:
Navigate to the Rules > Inspection Rules page.
Step 1
Select the checkbox of the rule (or rules) to change.
Step 2
Click Change Status.
Step 3
The selected rules are made inactive if active, and active if inactive and displayed on a different page.
To display inactive rules, select Inactive from the View dropdown list. To display active rules, select
Step 4
Active.

Duplicate a Rule

Duplicating a rule creates a new rule that is a copy of an existing system or user inspection rule. You
can edit all of the fields of a duplicate rule, but only the Source IP, Destination IP, and Device fields of
a system inspection rule. The original rule is left unchanged after duplication.
78-17020-01
Change the Source IP, Destination IP and Device fields of a System Inspection rule
Duplicate any Inspection Rule then edit the fields to make a new User Inspection Rule
Build a new User Inspection Rule with the Rule wizard
Edit any field of a User Inspection Rule
Make any rule active or inactive
Edit, delete, or add, a Rule Group
Working with System and User Inspection Rules
Appendix D, "System Rules and Reports."
User Guide for Cisco Security MARS Local Controller
21-17

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents