Assigning Tags upon Log Occurrence

Upon audit log occurrence, you can assign or remove tags to the assets (nodes, devices, users, wireless LANs) that generated the logs. By creating a search filter, you can automatically assign or exclude tags to corresponding assets when audit logs included in the search filter occur, allowing for their automatic assignment to or exclusion from separate policies.

Configuring Tags in Search Filter

  1. Go to Audit in the top menu.
  2. In the left menu, go to Logs > Search Filter.
  3. Click the Search Filter Name.
  4. In the Tags menu below, select Assign.
  5. Select the Search Target and Assignment Target to which tags will be assigned.
  6. Click the Add button to check the tags to assign, then click the Set button.
  7. Click the Modify button.

Untagging Assets in Search Filter

  1. Go to Audit in the top menu.
  2. In the left menu, go to Logs > Search Filter.
  3. Click the Search Filter Name.
  4. In the Tags menu below, select Remove.
  5. Select the Search Target and Assignment Target from which tags will be removed.
  6. Click the Add button to check the tags to remove, then click the Set button.
  7. Click the Modify button.