{"id":469,"date":"2010-07-06T20:20:33","date_gmt":"2010-07-06T20:20:33","guid":{"rendered":"https:\/\/fir3netwp.gmsrrpobkbd.com\/2010\/07\/06\/creating-a-cs-mars-rule\/"},"modified":"2023-02-04T02:10:08","modified_gmt":"2023-02-04T02:10:08","slug":"creating-a-cs-mars-rule","status":"publish","type":"post","link":"https:\/\/www.fir3net.com\/Security\/Siem\/creating-a-cs-mars-rule.html","title":{"rendered":"How to create a CS-MARS Inspection Rule"},"content":{"rendered":"
Within CS-MARS there are 2 types of rules. Inspection Rules and Drop Rules. Inspection Rules allow you to trigger events based on certain triggers such as keywords, source, destination etc. Drop rule is an exception rule which MARS uses to ignore a behaviour that would otherwise trigger an event.<\/p>\n
In this example we will configure a Inspection rule. First of all we need to define when this rule will trigger an event. For this example we will create an event every time someone saves an configuration change upon your Netscreen device. The syslog message for this is :<\/p>\n
Jul\u00a0 6 14:17:42 x.x.x.x ns200: NetScreen device_id=006403324004624\u00a0 [Root]system-information-00\r\n767: System configuration saved by [user] via web from host x.x.x.x to x.x.x.x:443 by [user]. \r\n(2010-07-06 19:17:41)<\/pre>\nSteps<\/strong><\/h3>\n
1. Click Rules | Inspection Rules | Add
\n<\/strong><\/p>\n<\/p>\n
2. This will take you through a wizard. For each stage select Any<\/strong>. Until you get to the Keyword section.
\n3. Enter the text you want CS-MARS to trigger on.<\/p>\n