Creating custom rules of MARCH

I want to be able to create a rule on:

[Info/UncommonTraffic/Chat]

[Info, UncommonTraffic, Chat, FileTransfer]

[Info/UncommonTraffic/Chat/Proxy]

.. .but be able to use the 'KEYWORD' field to trap on words like SSN / DOB and other keywords to trigger an e-mail action. Im guessing that this is not how the KEYWORD was intended to be used, but it is sure that looked like it when I put up. But as you may have guessed his does not work.

Can someone tell me what im doing wrong or how can I achieve this to trap for PHI in our Organization.

I've included a screenshot which may help to explain what page I'm looking at.

http://razors-edge.org/dropbox/screenshot.jpg

Thanks in advance.

Jim,

Good question! You did the correct support you use the 'keyword' option incorrectly. A device of MARCH is designed to parse and messages of aggregates of the declaration of the devices. In the example of "UncommonTraffic/Info/chat", typical features of statement are firewalls and IDS/IPS solutions. These all simply report on the presence of 'cat' traffic, no report the actual textual conversation. Unforunately the unit in MARCH is not really designed to work the way you want. Is this possible? Yes... you must have an application that is able to decode chat conversations before messages to MARS. In all honesty, it's a lot of work to make the MARCH camera doing something it's not designed to do. I hope this helps and don't forget to check my blog below for examples on how to use 'keywords' in a custom rule!

-Mike

http://CS-Mars.blogspot.com

Tags: Cisco Security

Similar Questions

  • FxCop Custom rule. Creating rules files

    Hello

    In Visual Studio 2013, I try to add a custom rule to enfore Logging to all methods of code. I created DLLs as mentioned in the msdn article below

    http://blogs.msdn.com/b/CodeAnalysis/archive/2010/03/26/how-to-write-custom-static-code-analysis-rules-and-integrate-them-into-Visual-Studio-2010.aspx

    But after you create and test the dll I'm not able to create the. RuleSet file. And looks like without creating a. RuleSet file is not possible to add the rule to the project in 2013 VS.

    Pls share if there is no work around for this.

    Thank you

    Parag Dave

    Parag,

    This forum is for the generic of troubleshooting and solving problems like yours, you can ask here

  • Custom rule works in the view RDF model?

    We create a model to view RDF from relational tables.

    Based on triplets mapped, we've created some custom rules in the rules of user base.

    Drop the involvement and create involvement again.

    But the query on the view model of RDF with defined rules of user base seems to be nothing happens.

    Could you please confirm if RDF model view support def rule base?

    Thank you.

    Note that user-defined inference would always regenerate involvement anyway.

    But, in addition, in the case of the model of RDFView materialized, the relational RDF conversion must be re-materialized if the content of the source tables changed since the last materialization of the RDF triple.

    Thank you

    -Smiled.

  • How to apply a custom rule just for a relational model?

    Hello

    My drawing has several relationship models, but I want to check custom rules or apply custom transformations just to a specific relational model.

    So, I created a 'personal library' called 'Custom design rules' with the following function:

    function checkColComments() {}

    result = true;

    ruleMessage ="";

    If (! column.getCommentInRDBMS ()) {}

    ruleMessage = 'no comment in RDBMS defined ";

    errType = "error";

    result = false;

    }

    return the result;

    }

    In the 'custom design rules", I created a rule"Comments column Check", referring to the library and the method created previously.

    But, even if I chose the "relational model" which I intend to apply this validation rule, run the script for all open models.

    This seems a bug (I use v3.3.0.747 DDM,) because it is asked to select the template to apply the script, but subsequently, this selection is ignored.

    I have not yet tried the v4.0EA to see if it has been resolved or not and the release notes does not refer to the list of the bugs fixed (or I have not found) as it was in version 3.3.0.747.

    No idea if I'm doing something wrong or if the bug still exists?

    Thank you!

    Hello

    design (including custom) rules are still applied on a relational model. I wasn't able to reproduce a case when this rule is broken.

    However, there is a bug in the 'Custom Design Rules' functionality and the rule is applied on what is called "current" model and model selected is ignored.

    Which works very well in the "Design rules" feature, where the selected model is used.

    As workaround for 'Custom Design Rules' - you can generate DDL by using "Generate the DDL" icon and this model will become as "current"relational model. "

    Philippe

  • Is it possible to create a rule for mail Search mail?

    I am trying to create a set of rules that would allow already read messages in folders by year. I can quickly find e-mail a year in research, it would be nice if I could create a rule right out of the research. I don't see this feature, but how can I create a rule which will find all the emails for a given year, and move them to a folder?

    Rules are usually set up for actions that are make again and again. What you describe will be just once, right?

    Do a search for the year you want, select all results, drag them to an appropriate folder.

  • Creating custom controls

    Hi guys,.

    I use labview to control test, but normally predispose the user interface as a windows with buttons, indicators, graphic controls program etc...

    But "they" want to be a process diagram that can be used to control and monitor the user interface stuff. Fine.   However, I created custom controls by changing true/false images on radio buttons.

    They work great when the program currently does not work, IE real gives an image, click on it and the image changes, great.  But when I run the software as soon as I move my mouse over the control, on what it shows default image for example a radio button, if I click and then move the mouse, it shows the picture its supposed to, but how can I stop it showing the radio button on a mouse?

    See the attached images.

    Thanks, Zac

    You can find a great video tutorial on how to create a system of buttons on the forums of JKI. For your particular purpose, you might want to look at the DSC Module, which has the commands you seem to be wanting to use.

  • This program is best used to create custom, forms to say double surveys and networks, etc.

    This program is best used to create custom, forms to say double surveys and networks, etc.

    http://answers.Microsoft.com/en-us/Office

  • Is it necessary to create additional rules not permitted for uses such as Regedit.exe etc when applying software restriction policy?

    Is it necessary to create additional rules not permitted for uses such as Regedit.exe etc when applying software restriction policy?

    Hello

    Please visit the following link. This should explain the software restriction policies in detail.

    http://TechNet.Microsoft.com/en-us/library/bb457006.aspx

  • Can we create a rule to capture the URL string in the Hits in the APM cartridge.

    Hi team,

    We have an obligation to create a rule/alarm alert when there is string "File not found" are there in the 'LINK' when we capture the Hits. Please let me know is possible to create this kind of rule in Foglight.

    Thank you

    Shashank Soni.

    To follow on what David said, you can find this useful guide:

    Configuration of the analyzers of success

    Hope this helps,

    Shay

  • Create a rule / older instant alarm

    Hello

    I am creating a rule / alarm, this updated fire for snapshots when have more than X days.

    I use the topology: VMWareSnapshot.

    Using an adaptation of the function to create the older snapshot report, I tried to create the rule.

    creationSnapshot = scope.creationTime.getTime ();

    now = new Date () .getTime ();

    diffHours = (now - creationSnapshot) / 3600000;

    diffDays = diffHours 24;

    (diffDays > = registry ("VMW:Old.) Snapshot.Warning'));

    When I test the condition in the script console, and in the rule condition, it works fine, but when the rule never fired.

    I forgot something?

    Thanks for any help or ideas

    Kind regards

    Alexander Ortiz

    Strategic Solutions Consultant

    Reference Dell | MCLA APM software, group

    Office + 57 312 568 4791, mobile + 57 312 568 4791
    E-mail [email protected]

    Hi Alex

    Yes, I'll try

    The rule definition:

    Only the State of alert is enabled:

    Condition

    Article: vBundle-1 VM Snap Shot age

    First - check VM list ignore

    Second - check VM has Snap Active

    Check the third - instant age

    List skip from reading the registry

    def IgnoreList is registry ("vBundle.vm.snapshot.age.ignore.list");.

    Get the name of VM

    def VMName1 = scope.get ("name");

    def boolean found = false;

    If (IgnoreList! = null) {}

    Found = IgnoreList.contains (VMName1) ;}

    If (found) return false;

    Check if the virtual machine has a snapshot active

    if(Scope.currentSnapshot == null) {}

    return false}

    Estimate the age of the snapshot

    def NumOfDays is registry ("vBundle.vm.snapshot.age.warning.days");.

    try {}

    creationTime = scope.currentSnapshot.get("creationTime").getTime ();

    If (creationTime == null) return false;

    now = new Date () .getTime ();

    diffHours = (now - creationTime) / 3600000;

    diffDays = diffHours 24;

    If (diffDays > = NumOfDays)

    Returns true;

    Otherwise, return false}

    catch (System.Exception e) {return false ;}

    Alarm message:

    [Warning] Virtual Machine: '@VMName' has a named snapshot: '@SnapshotName', it is longer than @WarningDays days. Remove the old clichés.

    There is no variable defined severity level.

    The Action is an EmailAction:

    mail.message

    VM (@VMName) has a snapshot that is @WarningDays the old days

    Discovers the alarm to: @foglight_rule_alarm_link

    mail. Subject

    [Warning] VM (@VMName) has an old cliché

    Behavior:

    Rule variables:

    Expression CriticalDays return register ("vBundle.vm.snapshot.age.critical.days");

    Expression FatalDays return register ("vBundle.vm.snapshot.age.fatal.days");

    Expression Nom_snapshot scope.currentSnapshot.name;

    VMName expression return scope.get ("name");

    Expression WarningDays return register ("vBundle.vm.snapshot.age.warning.days");

    Registry settings:

    vBundle.vm.snapshot.age.ignore.list

    vBundle.vm.snapshot.age.warning.days

    The days of warning STANDARD are 7 (Disclaimer), 14 (critic) and 30 (fatal).

    I hope this is clear for you

    If you want the critical and Fatal situation, let me know.

    Brian

  • Need help to create a rule to monitor the "DSDeviceTotalLatency" under "VMWDatastore".

    Hello all, I am very new to vFoglight and tasked to create a rule to control the property 'DSDeviceTotalLatency' of type 'VMWDatastore' topology.  Looking at existing rules, I see that I need to write a mini script on the tab 'Conditions and Actions '.  The problem is that I do not know how to reference this property and the command to use to recover.  Thank you in advance.

    At, it is simple, can be as simple as:

    scope of the rule to the VMWDatastore type on the tab 1

    condition on tab 2:

    If (#totalLatency # 10 >) {return true;}

    return false

  • How to create the rule to trigger only 5 and 20th of each month in Foglight

    Hi team,

    One needs to create a rule in Foglight that fire only a day as the 5th and 20th of each month and check the status. I tried to create it, but I've not found an option less create rule. I think we can do it by Time Driven option or calendar drove but I'm confuse. Can someone let me know how or the document where it mentioned.

    Thank you for your help in advance.

    Thank you

    Shashank Soni.

    That sounds more like a rule-based program.  First, create a new calendar and choose the monthly option and enter one of the days of the month.  I think it might be difficult to get a calendar to be true on two different days, you may create two programs and then create a rule for each.  We can be one simple copy of the other.  Once the calendar is created, you can create a rule, choose led calendar and choose one of your two annexes.

    Maybe someone can be smarter about how to create a monthly calendar for two different dates.

    I hope this helps.
    Jeff (I work for Dell)

  • Create a rule to delete Inbox mail

    How to create a rule to delete Inbox mail after so many days?

    The old version has allowed users to set for example mail to remove after 10 days or when a new mail from the sender received.

    I can't find how to do this on the new version, please help!

    Thank you

    I found it!

    This was previously the title of 'rules' and is now under "sweep".

    Thank you

  • Cannot create custom themes - change the wallpaper on the evolution of a theme the wallpaper on the other themes without apparent reason.

    Hi all

    I am trying to create a bunch of different themes, with various wallpapers and color schemes.

    I use right click on desktop-> personalization.

    At first, it seemed possible to create different themes by going to the image I want, right click on 'set as wallpaper', then enter right-click-on - desktop-> personalization, right click on the theme "non-registered" now watch the wallpapers, I just chose, then selecting "save us." This appeared to save the theme under personalization-> my themes.

    I got up to 5 different themes under "My themes" by doing this.

    But now, #5 theme, it works all of a sudden is no longer like that.

    Now, when the value a new picture as a wallpaper, it does not change only "Unsaved theme" for new wallpaper, it changes at the same time theme #5 to this wallpaper as well. When I save the new theme theme #6 and then go to change theme #5 to the wallpaper I had originally, it replaces theme #6 as well. It is impossible to change a wallpaper without changing both of them.

    I don't understand why it ehaves in this way. Why can't save just a theme and then not have to worry that it will be crushed randomly if I do something else with a completely different theme?

    Th information in this link can help you.
    http://www.maketecheasier.com/create-custom-Windows-8-themes/

  • can I create custom context menus? Can I use Push technology? With the browser?

    Anyone know if I can create custom context menus? Also, can I use Push technology? I vibrate the device? With the browser?

    Just try to clarify to make sure I understood the question.  The browser does not support the menu adding items to the BlackBerry menu (I don't know how tell - the menu that is displayed when you press the menu key on the BlackBerry). Java applications are.  You could build something in JavaScript (on 4.6 and later) who gave you menus, but it does not fire when the menu button has been pushed.

Maybe you are looking for

  • Is it possible to install XP on Satellite A300D-155

    Is it possible to install the Windows XP on this laptop (Satellite A300D-155 PSAKCE) operating system.Meabe other Os like Linux? Meabe know someone on tols, energy saveing, I looked on the website of AMD, but I found no anythink for Vista, tols ewery

  • Terminal Server does not

    Recently, I was going through the process of obtaining ImageMagick with the (sudo port install ImageMagick). I installed and like Xcode 3.2.6.  Then I installed MacPorts 2.3.4 10.6 Snow Leopard. Then I opened the terminal. The connection has shown. I

  • Card 32 GB not recognized

    I recently bought a Micro 32 GB SDHC card for my Fuze. I tested with H2TESTW and it tested fine, with no error reported. Only problem, the "rocket" did not recognize the card when using Rockbox. I had a similar problem when I bought the 16 GB card. I

  • I am trying to load my pictures on a site but my phone freezes and I can't download

    I start to download my photos site that I use always, but this time it wont let me upload, my laptop freezes and I have to turn off my laptop.

  • Hard drive SAS 1 TB per Dell PowerEdge 2900 [MS]

    Buonasera, avrei di una quotazione by a SAS hard drive need da 1 TB Seagate ST31000640SS da cute in UN Server knew sostituzione Dell PowerEdge 2900 Saluti, Enrico