User guide

iGuard/inSight User Guide
Release 7.0.0.4
101
2. Click on the name of the policy to open it.
3. Click on the name of the rule.
4. Select the Trashcan icon of the rule you want to delete.
5. Confirm or cancel the deletion when prompted.
What is an Action Rule?
An action rule is an extension of an active rule that defines some action that will be taken if a rule
produces a Hit. It is enabled by Active Directory.
Action rules are essentially templates that can be used whenever a situation arises that needs
special handling.
You can use an action rule to
send email notifications using dynamic variables to multiple recipients
create log entries in a syslog server
delegate responsibility for an incident
assign a status to an incident, or
prevent data loss.
Once you have defined an action, you can apply it to many different rules.
Create an Action Rule
An Action Rule triggers an action when a Hit is triggered by an existing rule. After it is created, it
must be activated by applying it to one or more rules it modifies.
1. Go to the Policies tab.
2. Click on Create New Action.
3. Name the new action rule.
Important: The characters * % @ + # ? , ' " cannot be used in name fields.
4. Define the actions you want to apply.
5. To send an automatic email notification, start by entering one or more addresses in
the "To" field.