Adding or editing conditions
There are two types of conditions; a triggering condition and a non-triggering condition. A triggering condition is a condition that happens now. A non-triggering condition is a condition that has occurred in the past. In policies, triggering and non-triggering conditions can be combined when evaluating a current condition against past conditions (for example, correlating high severity events (triggering) with past configuration changes (non-triggering).
This topic describes how to add or edit conditions for use in a policy and shows some examples.
To add or edit policy conditions
- Open the Conditions page by clicking the Policies tab, and selecting Policies > Conditions.
- Perform one of the following actions:
- To add a new condition, select Add.
- To edit an existing condition, select Edit
in the relevant row.
- To create a new condition by copying and editing an existing condition, select Copy
in the relevant row.
Enter or update information in the following fields:
The [confluence_table-plus] macro is a standalone macro and it cannot be used inline. Click on this message for details.
- Click Save.
Editing examples
The following figures show the editing of two out-of-the-box conditions, a triggering condition and a non-triggering condition. Click each figure to enlarge.
- Severity (0/1) Now condition, a triggering condition which detects the receipt of a high severity event from any device
- Change Detected Past condition, a non-triggering condition
In a policy, a non-triggering condition is evaluated after a triggering condition is received. For example, Severity (0/1) Now AND Change Detected Past can be used to correlate the high severity event with a prior configuration change.
Related topic
Viewing-the-conditions-listing