<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help with a rule (CSMARS).. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-help-with-a-rule-csmars/m-p/674032#M87244</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you can see in the new graphic, the incident indicates that it matched the rule and is a GREEN level event.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Mar 2007 18:10:15 GMT</pubDate>
    <dc:creator>mmorris11</dc:creator>
    <dc:date>2007-03-16T18:10:15Z</dc:date>
    <item>
      <title>Need help with a rule (CSMARS)..</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-a-rule-csmars/m-p/674030#M87238</link>
      <description>&lt;P&gt;I wrote a rule with the intent of it firing upon events originating only from public ip addresses AND only for yellow OR red severity levels.  However this rule still fires on green severity events.  Can any one see why from looking at the rule in the attached graphic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. Sorry about the double post.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:31:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-a-rule-csmars/m-p/674030#M87238</guid>
      <dc:creator>mmorris11</dc:creator>
      <dc:date>2019-03-10T10:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with a rule (CSMARS)..</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-a-rule-csmars/m-p/674031#M87240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you paste a picture of the actual events in an incident?  I believe green-level events can still be part of the incident, but you should still have at least 10 yellow or 1 red event also part of the incident.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 16:46:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-a-rule-csmars/m-p/674031#M87240</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-03-16T16:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with a rule (CSMARS)..</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-a-rule-csmars/m-p/674032#M87244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you can see in the new graphic, the incident indicates that it matched the rule and is a GREEN level event.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 18:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-a-rule-csmars/m-p/674032#M87244</guid>
      <dc:creator>mmorris11</dc:creator>
      <dc:date>2007-03-16T18:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with a rule (CSMARS)..</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-a-rule-csmars/m-p/674033#M87247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the problem.  There was a red severity event wrapped up in the session that was not visible until drilling all the way down to it.  Thanks for the ear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 18:18:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-a-rule-csmars/m-p/674033#M87247</guid>
      <dc:creator>mmorris11</dc:creator>
      <dc:date>2007-03-16T18:18:20Z</dc:date>
    </item>
  </channel>
</rss>

