About Event Action Rules - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Configuring Event Action Rules
This chapter explains how to configure event action rules. It contains the following sections:

About Event Action Rules

Event action rules are a group of settings you configure for the event action processing component of the
sensor. These rules dictate the actions the sensor performs when an event occurs.
The event action processing component is responsible for the following functions:
78-16527-01
About Event Action Rules, page 6-1
Signature Event Action Processor, page 6-2
Event Actions, page 6-3
Task List for Configuring Event Action Rules, page 6-4
Event Action Variables, page 6-4
Calculating the Risk Rating, page 6-6
Configuring Target Value Ratings, page 6-7
Event Action Overrides, page 6-7
Configuring Event Action Overrides, page 6-8
Event Action Filters, page 6-9
General Settings, page 6-14
Event Action Rules Example, page 6-19
Calculating the risk rating
Adding event action overrides
Filtering event action
Executing the resulting event action
Summarizing and aggregating events
Maintaining a list of denied attackers
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
6
C H A P T E R
6-1

Advertisement

Table of Contents
loading

Table of Contents