04-19-2018 01:40 PM - edited 03-12-2019 05:13 AM
HI all
I need help regading creating a custummize threshold for command accounting.
For example, if one of my enginner allow the rule on the ASA for source any destination any and service IP or one of the three match triggered from source, destination and service (any any service IP ).
ACS send the alert.
help me out guide me how to create the alert on ACS.
04-20-2018 10:52 AM
Hi
can any one kindly help me out.
so we can catch the culprite, who is allowing the rule or editing the rule.
04-20-2018 11:45 AM
You should be able to do this with Alarm Thresholds, that is if you have accounting configured on your network equipment already.
in ACS GUI:
1. go to Monitoring and Rports > Launch Monitor and Report Viewer
2. now go to Alarms > Thresholds
3. click "Create"
4. General tab: Enter a meaningful name
5. Criteria tab: fro the dropdown under Category select TACACS Command Accounting
6. in the Command box enter the command you want the alarm to trigger on
7. in the Device IP box enter the IP of the device you want this to apply to.
8. under Notifications tab enter the email address you want the alert sent to.
If you have several ACLs you want the alarm on, I believe you would need to configure an alarm for each one.
Some reading material
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide