6.2 Deploying Rule Sets

Complete the following steps to activate the rule set delivered with the latest version of UAM on your Agent computers. These rules that you configure perform event detection and alerting to send events that are filtered based on rules deployed to Sentinel.

To deploy rule sets to Agent computers:

  1. Start the UAM.

  2. Click Rules Manager.

  3. Make any changes you want to make to the default rule set displayed in the Rule Manager, customize the rule set as needed until the rule set is correctly configured for your environment.

  4. After you made changes to the rule set, save a copy by clicking File > Save/Save All and close the Save window.

  5. In the Available Hosts list, select the Agent computers on which you want to deploy the rule set.

  6. Click File > To Select Hosts.

  7. Click Select to deploy the rule set. It might take up to 30 seconds for the new rule set to take effect.

  8. Click Hosts > Scan All Hosts.

  9. Verify that the rule set is active on the Agent computers. The Sentinel column shows green cells for all agents with an active rule set.