Follow these steps to add a rule to match a condition for a particular appliance using the Central Management System appliance Web UI.
You can configure a rule to match traffic from a particular appliance that generated the alerts. You can add the relevant tag to this rule for all incoming alerts that contain the specified appliance record name.
Note
You can add or delete rules to match a condition for a particular appliance only using the Web UI.
In the Web UI, choose Settings > CM Settings > Alert Management > Rules.
Click Create Rule. The Create Rule window opens.
.png)
In the Rule Name field, enter the name of the rule.
In the Matching Criteria area:
Choose Appliance ID.
Choose equal to or not equal to as the operation to match the particular appliance ID.
Enter the appliance ID. Choose Appliances > Sensors to obtain the appliance ID of the managed Network Security appliance or the managed Email Security — Server appliance. The appliance ID is displayed in the Sensor ID column.
Click Add Condition. The appliance ID condition is added to the match criteria table.
In the Associated Actions area:
Choose Alert Tag Add to add a tag to an alert that includes the rule that contains the matched condition. Or choose Alert Tag Delete to delete a tag from an alert that includes the rule that contains the matched condition.
Enter any value you want to associate with the tag. Select an existing tag or tag/value pair, or enter a new tag or tag/value pair.
Click Add Action. The rule action configuration is added to the associated tag table.
Click Apply.
The following message appears:
.png)