Cisco Systems CL-28826-01 Security Camera User Manual


  Open as PDF
of 2616
 
39-7
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 39 Configuring Event Action Rules
Configuring Event Action Filters
You can inherit event action filter rules policies. Thus, you could configure a shared policy in Policy
view that includes filter rules that you want to share among all of your devices, inherit that rule for
each device (in Device view), and in Device view configure local filter rules that are unique to each
device. For more information on inheriting policies, see:
Creating a New Shared Policy, page 5-51
Inheritance vs. Assignment, page 5-6
Inheriting or Uninheriting Rules, page 5-43
Related Topics
Configuring Event Action Filters, page 39-4
Event Action Filters Page, page 39-7
Event Action Filters Page
Use the Event Actions Filters page to configure event action filter rules. Filter rules can remove specific
actions from an event or they can discard an entire event and prevent further processing by the sensor.
Event action filters are processed as an ordered list and you can move filters up or down in the list. Filters
let the sensor perform certain actions in response to the event without requiring the sensor to perform all
actions or remove the entire event. Filters work by removing actions from an event. A filter that removes
all actions from an event effectively consumes the event.
Before configuring event action filter rules, read the following topics:
Configuring Event Action Filters, page 39-4
Tips for Managing Event Action Filter Rules, page 39-6
Understanding the IPS Event Action Process, page 39-1
Tip Disabled rules are shown with hash marks covering the table row. To change the enabled/disabled status
of a rule, right click the rule and select Enable or Disable as appropriate. You can also change the status
when editing the rule.
Navigation Path
(Device view) Select IPS > Event Actions > Event Action Filters from the Policy selector.
(Policy view, IPS appliances and service modules) Select IPS > Event Actions > Event Action
Filters, then select an existing policy or create a new one.
(Policy view, Cisco IOS IPS devices) Select IPS (Router) > Event Actions > Event Action Filters,
then select an existing policy or create a new one.
Field Reference
Table 39-2 Event Action Filters Page
Element Description
Name The name of the filter rule.
Active Whether the signature is active.
This cell is not available for Cisco IOS IPS policies.