Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Monitoring rules

Folks,

when i look at default rule sets like "desktops" , towards the end of the page I see a bunch of rules in a seprate box which has "monitor" option checked, my question is what are these rules for , any thing different they are doing?

2 REPLIES
Silver

Re: Monitoring rules

Which Product/version are you using?

New Member

Re: Monitoring rules

Monitor rules simply alert you to an event happening on your agent.

For example, you want to know when a file is opened for read. Let's say a file on your server containing HR records. A monitor rule will log that to the CSAMC for your later investigations. Event details will contain useful information like time of event and the uid of the process that accessed the data.

There is a section in Chapter 5 of the CSA User's Guide that covers "The Monitor Action".

95
Views
0
Helpful
2
Replies