Create an Incident Scoring Rule
You can create rules for incidents by defining the matching condition and corresponding actions to take when a condition is met.
To create a rule for scoring incidents:
- Log in to Juniper Security Director Cloud.
-
Select Shared Services >
Insights > Rules >
Incident Scoring Rules.
The Incident Scoring Rules page is displayed.
-
Click the + icon.
The New Incident Scoring Rule page is displayed, where you can define rule’s condition and actions.
- In the Rule Name field, enter a unique name for the rule and select a matching condition from the list: Match Any or Match All.
- In the Condition section:
Select the type of incident from the list: File Hash, Threat Source IP, or URL.
-
For the selected incident, select mitigated by another event or not mitigated by another event as the condition.
Note:To add multiple conditions, click +.
-
In the Action section:
-
Select a required action from the list, such as Raise or Lower Severity, Set Severity (value), or Skip remaining rules.
-
Based on the action you have selected, provide additional data.
Note:To add multiple actions, click +.
-
-
Click OK.
A new rule is created and listed in the New Incident Scoring Rules page.
Click Enable or Disable to either enable the incident scoring rule or disable it.