Configuring rules to manage alert tags

Prev Next

You can configure rules that are used to manage alert tags on managed appliances by using the Central Management System appliance Web UI.

You can configure rules that match criteria and perform certain actions that are associated with the user-defined tags to filter incoming alerts on the managed appliances. Each rule can be associated with multiple actions. If the rule condition is matched, a tag will either be added to an alert to include the matched condition or deleted from an alert to exclude the matched condition. Each rule is carried out based on the priority order that you specified in the rules configuration table.

In the following example, the Central Management System appliance does not yet contain rules.

CM_AlertRuleCreate_scap.png

This section covers the following information:

Usage Guidelines

Follow these usage guidelines when you configure rules that are used to manage tags on managed appliances:

  • The name of the rule can contain alphanumeric characters.

  • Only unrestricted tags can be created by using rules.

  • A rule must contain at least one condition and one action.

  • A rule cannot contain multiple values for a single condition.

  • A single rule can contain different criteria entries (but not duplicate entries).

  • A single rule can contain multiple actions.

Prerequisites
  • Access to the Web UI of the Central Management System appliance as Admin or Analyst