I posted this on the Cisco MARS User group on Google, but thought it is best to cover it here as well.
I just read that this can not be done using a keyword, but am interested if there is any other way of getting the same (or equal) result.
Is there any way to configure a false positive drop rule based on a
keyword in the raw message? I have a user that consistantly pushes the
switch port interface utilization above 90% - this is normal activity
that happens throughout the day. We get 20 - 30 email alerts per day
on this. I would like to configure a drop rule that will just drop
this incident if this user's interface is specified in the raw
message. Or maybe there is another way to get the same result?