Create rules from log entries
You can use log entry details to generate new rules.
To convert a log entry to a rule, the log entry must be created based on a rule (the entry contains a rule tag). Creating a rule this way allows you to make quick exceptions to the current policy. You can create the following types of rules:
- A rule that allows a connection from an entry that logs stopped traffic
- A rule that stops a connection from an entry that logs allowed traffic
- A rule that changes the log level or stops the logging of matching connections
Steps
New Rule Properties dialog box
Use this dialog box to convert a log entry to a rule and add it to a policy.
| Option | Definition |
|---|---|
| Policy | The policy that the rule will be added to. |
| Select | Opens the Select Element dialog box. |
| Comment (Optional) |
A comment for your own reference. |
| Rules table | Shows the rule that will be added. You cannot edit the rule in this dialog box. |
| Action | Specifies the
Action. All actions create the displayed rules at the beginning of the first insert point in the selected policy.
|