modify_incident_rule

Enables or disables a specific incident rule or rule set. (Updates all rules in the rule set.)

Format

emcli modify_incident_rule
      -action=enable|disable 
      -type=ruleset|rule 
      -rule_set_name=<name_of_rule_set>
      [-owner=<owner_of_rule_set>]
      [-rule_name=<name_of_rule>]

[ ]  indicates that the parameter is optional

Options

  • action

    Action to be performed. Supported actions are enable and disable.

  • type

    Disables a specific rule or the entire rule set.

  • rule_set_name

    Name of the rule set to which you would like to apply the action.

  • owner

    Owner of the rule set. If multiple rule sets exist with same name, the rule set owner is used to identify the rule set.

  • rule_name

    Name of the specific rule to which the action will apply.

Examples

Example 1

This example enables 'rule set 1' and all child rules.

emcli modify_incident_rule -action='enable' -type='ruleset' -rule_set_name='rule set 1' 

Example 2

This example disables a single rule named 'rule 1' within 'rule set 1'.

emcli modify_incident_rule -action='disable' -type='rule' -rule_set_name='rule set 1' -rule_name='rule 1'