You can configure rules that are used to manage alert tags on managed appliances by using the Central Management System appliance Web UI.
You can configure rules that match criteria and perform certain actions that are associated with the user-defined tags to filter incoming alerts on the managed appliances. Each rule can be associated with multiple actions. If the rule condition is matched, a tag will either be added to an alert to include the matched condition or deleted from an alert to exclude the matched condition. Each rule is carried out based on the priority order that you specified in the rules configuration table.
In the following example, the Central Management System appliance does not yet contain rules.
.png)
This section covers the following information:
Adding a Rule to Match a Condition for a Particular IP Address Using the Web UI
Adding a Rule to Match a Condition for a Particular VLAN Using the Web UI
Adding a Rule to Match a Condition for a Particular Appliance Using the Web UI
Adding a Rule to Match a Condition for a Particular Product Type Using the Web UI
Adding a Rule to Match a Condition for a Particular Severity Type Using the Web UI
Adding a Rule to Match a Condition for a Particular Email Using the Web UI
Usage Guidelines
Follow these usage guidelines when you configure rules that are used to manage tags on managed appliances:
The name of the rule can contain alphanumeric characters.
Only unrestricted tags can be created by using rules.
A rule must contain at least one condition and one action.
A rule cannot contain multiple values for a single condition.
A single rule can contain different criteria entries (but not duplicate entries).
A single rule can contain multiple actions.
Access to the Web UI of the Central Management System appliance as Admin or Analyst