Chapter 21
Rules
Working with System and User Inspection Rules
Navigate to the Inspection Rules page by clicking the Rules tab.
You can perform the following actions with Inspection Rules:
•
•
•
•
•
•
When you add or edit a rule, you must click Activate to enable the changes.
Note
Note
Upgrade the MARS software regularly to obtain new and updated System Inspection rules. For more
information, see the Install and Setup Guide for Cisco Security Monitoring, Analysis, and Response
System. To view a list of System Inspection rules, see
Change Rule Status—Active and Inactive
The CS-MARS correlation engine continuously tests only active rule criteria against incoming events to
identify incidents. Inactive rules do not consume resources used for realtime operations.
A rule cannot be deleted, it can be made active or inactive.
Note
To change the status of a rule, follow these steps:
Navigate to the Rules > Inspection Rules page.
Step 1
Select the checkbox of the rule (or rules) to change.
Step 2
Click Change Status.
Step 3
The selected rules are made inactive if active, and active if inactive and displayed on a different page.
To display inactive rules, select Inactive from the View dropdown list. To display active rules, select
Step 4
Active.
Duplicate a Rule
Duplicating a rule creates a new rule that is a copy of an existing system or user inspection rule. You
can edit all of the fields of a duplicate rule, but only the Source IP, Destination IP, and Device fields of
a system inspection rule. The original rule is left unchanged after duplication.
78-17020-01
Change the Source IP, Destination IP and Device fields of a System Inspection rule
Duplicate any Inspection Rule then edit the fields to make a new User Inspection Rule
Build a new User Inspection Rule with the Rule wizard
Edit any field of a User Inspection Rule
Make any rule active or inactive
Edit, delete, or add, a Rule Group
Working with System and User Inspection Rules
Appendix D, "System Rules and Reports."
User Guide for Cisco Security MARS Local Controller
21-17