Documentation forSecurity Event Manager

Create a new rule

  1. Log in to the SEM Console.

  2. On the toolbar, click the Rules tab.
  3. On the Rules toolbar, click Create new rule.

    The Create new rule screen displays in the console. The left column displays several categories you can add to a rule, including:

  4. Click a category to display the entities it contains. Click an entity to display the entity fields it contains.

    Use the search box to locate entitles and entity fields. All matches are highlighted, as shown below:

  5. Drag the appropriate entity or entity field into the rule definition builder.

    When you drag a value into the rule builder, the correct drop location is shown with a blue line.

    Moving an entity or entity field to the right pane creates a condition. If it is an entity, by default the condition will be created showing that it occurred. For example:

    If required, click occurred to change the value to did not occur. If it is an entity field, by default the condition is created, showing that the field is equal to [blank].

    Click is equal to to change to an alternative operator as required. Enter a value for the comparison, click to display the available value, or drag across another field as appropriate.

  6. After you configure part of a rule, you can change it by moving the cursor over it to display the rule builder toolbar.

    This enables you to:

    • Apply occurrence settings for this part of the rule by clicking the icon
    • Edit the expression by clicking the icon
    • Delete the expression by clicking the icon
    • Add an addition entity or entity field by clicking the icon
  7. To add subsequent rule parts, click the rule definition icon, and then create the condition as shown above.

  8. From the drop-down list, select an option, enter a specific value or keyword directly.

    By default rule parts are linked with And operators to show that all rule parts must be true. To change an And operator, click And, and then select Or.

    By default rule parts are linked with And operators to show that all rule parts must be true. To change an And operator, click And, and then select Or.

    By default, the actions are triggered whenever the conditions that make up the rule are true. However, you can change this so that the rule has to be true multiple times. For information, see Occurrence settings.

  9. Click Next to display Details and actions.

  10. Under Details and actions, enter a rule name and optional description.
  11. Click the icon to select one or more optional tags for this rule.

    Tags make it easier to catalog and find rules.

  12. Turn off the Click Enable rule after saving THIS option if you want to save a rule without adding an action. You can enable the rule afterwards from the Rules screen.
  13. Turn on the Enable test mode option if you want to use this rule test mode. The rule will run but will not trigger any actions. This option allows you to view how the activated rule will behave without disrupting your network. You can Identify test mode rules in your list by the Test icon .

  14. Click Add new action to add an action when the rule triggers.

  15. Enter a search term or select an action from the list, and then click Next.
  16. Define the trigger action, and then click Add.

    SEM provides over 30 actions that can be triggered using rules, ranging from Sending a pop-up message to Disabling Networking. For each the procedure is similar: select or enter the required parameters, and click Add.

    You can add multiple actions to a rule by clicking Add new action.

  17. Click Create when you have finished adding actions to this rule. The rule is now available in the list of rules.

    To edit, delete, and toggle test mode, click the vertical ellipsis next to a rule.