ADM, Deep Packet Inspection, Advanced Syslog Parser, and Correlation rules can be viewed, copied, and pasted. Custom rules of these types can be modified or deleted. Standard rules can be modified, but must be saved as a new custom rule.
In the Rule Types pane of the Policy Editor, select the type of rule that you want to work with.
To view custom rules:
Select the Filter tab in the Filters/Tagging pane.
At the bottom of the pane, click the Advanced bar.
If you want to view a Generic - Advanced Syslog Parser rule, clear the Device Type ID field.
In the Origin field, select user defined, then click Run Query
.
To copy and paste a rule:
Select a predefined or custom rule.
Select → , then select → .
The rule you copied is added to the list of existing rules, with the same name and settings.
Note
For ASP and Filter Rules, the rule order is copied as part of the copy process.
Check that the ordering of the new rule will not adversely affect data parsing ( → ) or ( → ).
To change the name, select → .
To modify a rule:
Highlight the rule you want to view, then select → .
Change the settings, then click OK. If it's a custom rule, it's saved with the changes. If it is a standard rule, you are prompted to save the changes as a new custom rule. Click Yes.
Note
If you did not change the name of the rule, it is saved with the same name and a different sigID.
You can change the name by selecting the rule, then selecting → .