Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

To handle a few common inbound event types, all in-house relays have four predefined rules. Three of these are designed to receive events from specific sources incapable of applying tags, and the fourth rule simply acts as a forwarder for events that are already tagged. These predefined rules use ports 12999-13002. This means you cannot use these ports to set up custom rules. 

...

  1. Log into your Devo account.

  2. Go to Administration → Relays and click the relay name to pen the relay details window to the Relay Input (Rules) tab.

  3. To set up a new rule, click the Add Rule button.

    Image RemovedImage Added
  4. The Rule Definition window opens. Set up your new rule:

    1. Type a unique Rule name to your new rule.

    2. (optional) Although the Description is not mandatory, it is a good practice.

    3. Identify the Source port on which the relay will receive the inbound events. It is good practice to dedicate a single port to a single event source. Example: If you are setting up the Alarm Feed, you should type 13003

    4. Enter the Devo tag in the Target tag field. For example: if you are setting up the Alarm Feed, you should type proxy.zscaler.zia.alert.syslog 

    5. Select the Sent without syslog tag checkbox.

    6. (optional) Select the Stop processing checkbox if you don't want the event to be subject to any subsequent relay rules. If this is the only rule that will run on events received on the specified port, this is not necessary.

    7. Click on ADD RULE to save the new relay rule.

      Image RemovedImage Added
  5. When your rules are ready, click on APPLY CONFIGURATION to send the updates to Devo Relay.

    Image RemovedImage Added


Your rule/s will be activated in your relay in no time.