How to create a CS-MARS Inspection Rule
Within CS-MARS there are 2 types of rules. Inspection Rules and Drop Rules. Inspection Rules allow you to trigger events based on certain triggers such as keywords, source, destination etc. Drop rule is an exception rule which MARS uses to ignore a behaviour that would otherwise trigger an event.
In this example we will configure a Inspection rule. First of all we need to define when this rule will trigger an event. For this example we will create an event every time someone saves an configuration change upon your Netscreen device. The syslog message for this is :
Jul 6 14:17:42 x.x.x.x ns200: NetScreen device_id=006403324004624 [Root]system-information-00767: System configuration saved by [user] via web from host x.x.x.x to x.x.x.x:443 by [user]. (2010-07-06 19:17:41)
1. Click Rules | Inspection Rules | Add
2. This will take you through a wizard. For each stage select Any. Until you get to the Keyword section.
3. Enter the text you want CS-MARS to trigger on.
4. Carry on through the wizard. At the end Apply the changes.
5. Now when you go into the Incident Rule section again you will see your new rule. By default your new rule will be activated.
Within the previous syslog message you will notice that the message ID is 00767. CS-MARS has a list of all the device message types/IDs which is calls event types. This is useful as this allows you to build rules based on event types rather then just using keyword strings.