Adding or editing keywords


Keywords can be one of the following types:

  • Event: Any event that is logged to the Event Log (for example from external syslog or user event).
  • Change: TrueSight Network Automation detected a configuration file change or an OS image change.
  • Discrepancy: Network Automation detected a configuration file or an OS image discrepancy (for example difference between the trusted production configuration and the current configuration).

 

Note

The Change Detected keyword is used to detect changes to the Running, Startup, and other configurations and to the operating system. To detect hardware changes, use the Hardware Change Detected keyword (Type=Event, Category=Device, Event=Hardware inventory has been updated.).

Click here to view the predefined keywords that are delivered with TrueSight Network Automation and, which assist in establishing policies.

Keyword name

Description

All Compliance Violations Cleared

All compliance violations on the current configurations have been cleared.

All Discrepancies Cleared

All discrepancies between running versus startup, running versus trusted running, startup versus trusted startup, and OS image are cleared on the device.

Change Detected

A change has been detected in a configuration file.

Compliance Violation Detected

A compliance violation on a device was detected. Compliance violation events are logged for rules in enabled and assigned compliance rule sets.

Config Change Event

A potential configuration change has occurred on a device.

CPU Usage

Detects high CPU usage reported on a device.

Denial of Service

A denial of service event has been received from a device.

Deploy to Active Request Failed

A user or policy-based Deploy to Active action for a device has failed.

Discrepancy Detected

A discrepancy has been detected between the device's trusted production configuration and the current configuration.

Duplicate IP Address

A duplicate IP address event has been received from a device.

External Change Task Close Failure

The External Change Task Close task fails.

Hardware Change Detected

The system has detected a hardware change on a device (for example, new or removed board, flash, or memory chip.)

Link Down

A link down event has been received from a device.

Memory Event

A memory event has been received from a device.

OS Version Change

A change to the operating system version has been detected.

Remediate Request Failed

A user or policy Remediate action with a rule, rule set, or all assigned rules has failed for a device.

Security Event

A security event has been received from a device.

Severity (0/1) Event

A high severity event (0/1) has been received from the device.

Snapshot Request Failed

A user or policy-based configuration snapshot for a device failed.

System Reload

A system reboot has been detected on a device.

This topic describes how to add, edit, or copy keywords for policy conditions and also shows some examples.

To add, edit, or copy keywords for policy conditions

  1. Open the Keywords page by clicking the Policies tab, and selecting Policies > Keywords.
  2. On the Keywords page, perform one of the following actions:
    1. To add a new keyword, click Add.
    2. To edit an existing keyword, click Edit.
    3. To create a new keyword by copying and editing an existing keyword, click Copy.
  3. Enter a unique name for the keyword, up to 40 characters.
  4. Select the type of keyword: Event, Change, or Discrepancy. You cannot edit the keyword type after it is saved.
  5. Enter or update information in the displayed fields:
    • For an Event keyword:

      The [confluence_table-plus] macro is a standalone macro and it cannot be used inline. Click on this message for details.

    • For a Change keyword:

      The [confluence_table-plus] macro is a standalone macro and it cannot be used inline. Click on this message for details.

    • For a Discrepancy keyword:

      The [confluence_table-plus] macro is a standalone macro and it cannot be used inline. Click on this message for details.

  6. Click Save.

Back to top

Editing examples

The following figures show the editing of out-of-the-box keywords, one of each type (Change, Event, and Discrepancy). Click each figure to enlarge.

Editkeyword_Change.png Editkeyword_event.png Editkeyword_discrep.png

Back to top

Related topic

Viewing-the-keywords-listing

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*