|Applies to Product:||USM Appliance™||AlienVault OSSIM®|
Policies can be created with actions or without actions in instances where the consequences are SIEM, logger, and forwarding consequences. For information about how to create an action, see Create an Action. An action for the policy must be created first.
To create a new policy
- Go to Configuration > Threat Intelligence > Policy.
- If you want to create a policy for an external event, click New in Default Policy Group. If you want to create a policy for a system event, click New in Policies for Events Generated in Server.
Enter a name in the Policy Configuration page.