The Actions tab enables you to select a trigger, then specify the action to take when that trigger occurs.
To specify an action:
Open the profile in the profile editor (double click the profile in the Navigator panel).
In the Inspect/Edit panel, click the Actions tab.
Before you add an action, specify when to take the action (the trigger). Select one of the following trigger options:
Trigger Option |
Description |
---|---|
On Pattern Discovered |
This specifies that the action be taken the first time a new pattern appears. Choose this option for assigning new patterns to an analyst to investigate. |
On Pattern |
This specifies that the action will be taken if a new pattern is repeated. Choose this option for ongoing operations. |
Click Add and select one of the following options:
Action Option |
Description |
---|---|
Annotate Pattern |
In the dialog box, enter the following values and click OK:
|
Set Event Field |
In the dialog box, enter the following values and click OK:
|
Send Notification |
Specify a notification group in the Notification Group drop-down menu.
|
Execute Command |
In the dialog box, enter the following values and click OK:
|
Execute Connector Command |
Specify a command to be executed at the SmartConnector reporting the events, such as pause or stop/start event flow. Enter the following values and click OK:
|
Export to External System |
You can export the pattern to an external tracking system, if you configured it to operate with ESM. Click OK. |
Active List |
You can add (or remove) a pattern to an active list, where its event details are available to other correlation tools for reference.
|
Session List |
You can add a pattern to a session list, or terminate a session list based on a pattern, where its event details are available to other correlation tools for reference.
|
The action summary will be displayed in the Actions tab. To remove lines that are not used, click Hide Empty Triggers.