In this task, we try to match the same events selected in Task 2. We want to use the
same event types
same source and destination IP addresses
same destination port
Click the green plus (+) sign at the right side of the first rule, under the Action heading.
The New Rule window displays.
In Rule name > Plugin, type "cisco-asa" in the search box, and then click Cisco-ASA.
In Rule name > Plugin > Event Type, click Plugin SID from rule of Level 1.
This selects the same event types as in the level 1 rule.
In Rule name > Plugin > Event Type > Network,
In Source Host / Network, under From a parent rule, select "Source IP from level 1".
This selects the same source IP address as in the level 1 rule.
Leave the Source Ports empty.
In Destination Host / Network, under From a parent rule, select "Destination IP from level 1".
This selects the same destination IP address as in the level 1 rule.
In Destination Port(s), under From a parent rule, select "Destination Port from level 1".
This selects the same destination port as in the level 1 rule.
In Rule name > Plugin > Event Type > Network > Reliability, click +2.
Note: In this step, you can either choose an absolute value (left column) or a relative value (right column). If you select a relative value, as we did, USM Appliance adds the value to the reliability set in the previous rule.
Click Finish. The New Directive window closes.
In the Timeout column, click "None" in the second rule, type "30" (seconds), and then click OK.
In the Occurrence column, click "1" in the second rule, type "100", and then click OK