Popular
Latest Articles
- Oracle 11g / Fedora 13 - Error in invoking target 'agent nmb nmo nmhs tclexec'
- Cisco Router Zone Based Firewall Configuation Guide - Video Tutorial
- Installing GNS3 0.7.2 onto Fedora 13
- Configuring a Pre-Shared Site to Site VPN between 2 Cisco Routers
- IPv4 Subnetting Notes
- Types of IDS Alerts
- How to run vSphere using SSH tunnelling
- Compiling Rancid on an x86 Solaris 10 platform
How to create a CS-MARS Inspection Rule
Tuesday, 06 July 2010 20:20
Within CS-MARS there are 2 types of rules. Inspection Rules and Drop Rules. Inspection Rules allow you to trigger events based on certain triggers such as keywords, source, destination etc. Drop rule is an exception rule which MARS uses to ignore a behaviour that would otherwise trigger an event.
In this example we will configure a Inspection rule. First of all we need to define when this rule will trigger an event. For this example we will create an event every time someone saves an configuration change upon your Netscreen device. The syslog message for this is :
Steps
1. Click Rules | Inspection Rules | Add
2. This will take you through a wizard. For each stage select Any. Until you get to the Keyword section.
3. Enter the text you want CS-MARS to trigger on.
4. Carry on through the wizard. At the end Apply the changes.
5. Now when you go into the Incident Rule section again you will see your new rule. By default your new rule will be activated.
Additional Notes
Within the previous syslog message you will notice that the message ID is 00767. CS-MARS has a list of all the device message types/IDs which is calls event types. This is useful as this allows you to build rules based on event types rather then just using keyword strings.


