Sys Maintenance: Policies Tab

Document created by RSA Information Design and Development on Sep 14, 2017Last modified by RSA Information Design and Development on Oct 13, 2017
Version 10Show Document
  • View in full screen mode
  

The required permission to access this view is Manage services.

What do you want to do?

                       
RoleI want to ...Show me how
AdministratorView the policies NetWitness Server and ServicesManage Policies
AdministratorAdd, Edit, Duplicate, and Delete Policies Manage Policies

Related Topics

Manage Policies

Quick Look

The figure depicts the Policies view.

Policy view

             
1 Policies Panel
2 Policy Detail Panel
  1. Go to ADMIN > Health & Wellness.
  2. Click the Policies tab.

Policies Panel

In the Policies panel, you can add or delete policies for hosts and services in this panel.

                                       
FeatureDescription
Add icon Displays available service types to create a new policy . Select one so that you can define a policy or policies for it.
Delete icon Deletes the selected policy from the Policies panel. You can only delete one policy at a time.
Edit icon Allows you to change the name of the policy.
Duplicate icon Creates a copy of the selected policy. For example, if you select First Policy and click Duplicate icon, NetWitness Suite creates a copy of this policy and names it First Policy (1).
Click to open the list of options Expands the list of policies under the services and hosts in the Policies panel.
Click to close the list of options Contracts the list of policies under the services and hosts in the Policies panel.
 

List of:

  • Services and hosts for which you have defined policies.
  • RSA standard policies that you can apply to hosts and services.

Policy Detail Panel

The Policy Detail panel displays the policy selected from the Policies panel.

                                                                                                                   
FeatureDescription
SaveSaves any changes you made in this panel.
Policy TypeDisplays the type of policy you selected.
Modified DateDisplays the last date this policy was modified.
Checkbox EnableSelect and deselect this checkbox to enable and disable the policy.
Services
Add drop-down list

Displays menu in which you select:

  • Groups to display the Groups dialog from which you select service groups to this policy.
  • Service/Host to display the Services/Hosts dialog from which you select services to add to this policy. If policy type is Host, the menu will have Host not Service. You can select services based on policy type.
Delete icon Deletes the selected service or group from this policy.
Rules
Add icon Displays the Add Rule dialog in which you define a rule for this policy.
Delete icon Deletes the selected rule from this policy.
Edit icon Displays the Edit Rule dialog for the selected rule.
Policy Suppression
Add icon Adds a policy suppression timeframe row. 
Delete icon Deletes the selected policy suppression timeframe row.
Time ZoneSelects the time zone for the Policy from the drop-down list.  This time zone applies to both Policy Suppression and Rule Suppression.
Checkbox Selects the checkbox to select a policy suppression timeframe row.
DaysDays of the week that you want to suppress the policy according to the time range specified. Click on the day of the week that you want to suppress the policy.  You can select any combination of days including all days.
Time RangeTime range during which the policy is suppressed for the days selected.
Notifications
Add icon Adds an EMAIL notification row. 
Delete icon Deletes the selected policy suppression timeframe row.
Notification SettingsOpens the Notification Servers view in which you can define the Email notification settings.
Checkbox Selecting the checkbox selects a policy suppression time frame row.
Output

The type of notification defined on the Global Notifications page. Can be email, SNMP, Syslog, or Script.

Recipient

The name of the person receiving the notification.

Notification ServerSelect the EMAIL notification server. See 'Configure Notification Servers' in the System Configuration Guide for the source of the values in this drop-down list.
Template

Select the Template for this EMAIL notification. RSA provides the Health & Wellness Default SMTP Template and the alarms template. See Configure Notification Templatesin the System Configuration Guide for the source of the other values in this drop-down list.

Note: Refer to Include the Default Email Subject Line if you want to include the default Email subject line from the Health & Wellness template in your Health & Wellness Email notifications for specified recipients.

Groups dialog

                                 
FeatureDescription
Groups panel
Name

Displays the service groups you have defined. You can select:

  • All to display all your services in the Services panel.
  • A group to display the services in comprise that group in the Services panel.
Services panel
NameDisplays the name of the service.
HostDisplays the host on which the service is running.
TypeDisplays the type of service.

Rules Dialog

                                                                  
FeatureDescription
Checkbox EnableSelect and deselect this checkbox to enable and disable the rule for this policy.
NameEnter the name of the rule.
Description

Enter the description of the rule. RSA suggests that you include the following information in this field.

  • Informational description - purpose of the rule and what problem it monitors.

  • Remediation - steps to take to resolve the condition that triggers the alarm for this rule.

Severity

Select the severity of the rule. Valid values are:

  • Critical
  • High
  • Medium
  • Low
Statistic

Select the statistics you want to check with this rule. You can select:

  • Statistical category from the left drop-down list.
  • Statistic from the right drop-down list.

Note: For Public Key Infrastructure (PKI) policy, select PKI in the category and statistics as any one of the following:
- NetWitness Server PKI Certificate Expiration - Displays the time left before the certificate expires.
- NetWitness Server PKI CRL Expiration - Displays the time left before the Certificate Revocation List (CRL) expires.
- NetWitness Server PKI CRL Status - Displays the current status of the CRL.

Please refer to the System Stats Browser View for examples of the statistics you may want to check with a rule. 

Alarm Threshold

Define the threshold of the rule that will trigger the policy alarm:

  • Amount

    Note: For CRL expiry the supported format is ddddhhmm, for example:
    - 10000 represent 1 day
    - 2359 represent 23 hours and 59 minutes
    - 10023 represent 1 day and 23 minutes
    - 3650100 represent 365 days and 1 hour

  • Time in minutes
Recovery

Defines when to clear the threshold of the rule:

  • Operator:

    • For NetWitness Suite 10.5 (=, !=, <, <=>, or  >=
    • For NetWitness Suite 10.5.0.1 and later (See Threshold Operators below)
  • Amount
  • Time in minutes
Rule Suppression
Add icon Selecting this option allows you to add a rule suppression timeframe row. 
Delete icon Selecting this option allows you to delete the selected rule suppression time frame row.
Checkbox Selecting the checkbox allows you to select a rule suppression time frame row.
Time Zone: time-zoneDisplays the Policy time zone.  You select the time zone for a policy in the Policy Suppression panel.
DaysDays of the week that you want to suppress the rule according to the time range specified. Click on the day of the week that you want to suppress the rule.  You can select any combination of days including all days.
Time RangeTime range during which the rule is suppressed for the days selected.

Threshold Operators

The Alarm Threshold and Recovery Threshold fields in the Rules dialog prompt you for either numeric or string operators based on the statistic criteria you specify.

       
Numeric operators drop-down menu: Numeric operators drop-downString operators drop-down menu: String operators drop-down
You are here
Table of Contents > References > Health and Wellness > Policies View

Attachments

    Outcomes