Specifications
Create/Edit Search Scope Rule
This view lets you create rules that determine which search scope will be used when a specific threat arrives.
Each search scope rule defines a set of conditions (sender id, threat subnet, etc.) and a search scope to use
when the conditions are met.
You can access this window from the ASM Configuration window's Search Scope Definitions panel. Select
the Advanced Search Mode, then click the Create or Edit button in the Search Scope Rules section.
Click areas in the window for more information.
Rule Name
The name given to this rule. The name can be any character string, up to 64 characters.
Rule Conditions
The following conditions are compared against the information returned from Dragon to determine the
applicability of this rule. When the information from the event information matches these conditions, then the
Search Scope specified is used as the ASM search scope.
Select Sender Identifiers
This area lets you select one or more sender identifiers to be compared against the sender identifier
returned in the event, to determine whether or not to use the Search Scope specified as the ASM
search scope.
Match Any − This is an unconditional match for the Sender ID.•
Create/Edit Search Scope Rule 166










