Content Library Tab

The netwitness_configure.png (CONFIGURE) > Policies view contains two tabs: Configuration and Content.

The CONTENT tab has Content Library, Policies and Groups on the left panel.

Below is an example of the Content > Content Library tab:

netwitness_121_contentlibrary_1122.png

1

Toolbar

2

Rule List Pane

  • Name - Name of the rule.

  • Medium - Medium through which the rule is created.

  • Last Updated - Displays the time when the rule is updated.

  • Policies - Policies to which the rule is applied.

You can also sort on any column. If you mouse over a column header, a sort icon is displayed: . Click the netwitness_sort.pngicon to sort by the selected column.

Create New Rule dialog:

Below is an example of the Create new rule dialog:

netwitness_121_createnewrule_1122.png

The table describes the information and options in the Create New Rule dialog:

Field Description
Rule Name Name of the new rule. The name should be unique.
Condition

Condition for the new rule. You can apply two types of conditions for the rule.

Normal mode:

It gives suggestions for supported metas (ip, host and so on) and operators (“=”, “Not Equal To”, “Contains”, “Exists” and so on).

The entered condition will be enclosed in a ‘Pill’. When you enter multiple conditions, the conditions are automatically joined by an ‘AND’ operator. On clicking the ‘AND’ operator, you can toggle between ‘AND’ and ‘OR’ operators.

Advanced:

You can customize the conditions as a free form text.

Medium Medium through which the rule is created. For a network rule, the value of medium is selected as Packet as default and the user cannot edit it.
Session Data Session data for the new rule. Indicates if the rule processing should stop, keep, filter or truncate when the session data is running.
Session Options Session options for the new rule. Indicates if the session options should be alert, forward or transient.
Alert On Conditions for which the alert should be turned on.
Save Saves the settings and closes the Create New Rule dialog.
Cancel Cancels the operations.

Clone Rule dialog:

Below is an example of the Clone rule dialog.

netwitness_121_clonerule_1122.png

The table describes the information and options in the Clone Rule dialog:

Field Description
Enter Name for Cloned Rule Name of the cloned rule. The name should be unique.
Clone

Clones the rule and closes the Cone Rule dialog.

Cancel Cancels the operation.