| Action | Description | 
|---|---|
| Tag Source IP from Event | Run this action to label the source IP address based on an event | 
| Tag Destination IP from Event | Run this action to label the destination IP address based on an event | 
| Tag Source IP from Alarm | Run this action to label the source IP address based on an alarm | 
| Tag Destination IP from Alarm | Run this action to label the destination IP address based on an alarm | 
| Tag Source IP Address from Rule | Run this action to label the source IP address based on a predefined rule | 
| Tag Destination IP Address from Rule | Run this action to label the destination IP address based on a predefined rule | 
| Remove Tag from Source IP Address | Run this action to remove a tag from the source IP address | 
| Remove Tag from Destination IP Address | Run this action to remove a tag from the destination IP address based on an event | 
| Remove Tag from Source IP from Alarm | Run this action to remove a tag from the source IP address associated with an alarm | 
| Remove Tag from Destination IP from Alar | Run this action to remove a tag from the destination IP address associated with an alarm | 
- In USM Anywhere, go to Data Sources > BlueApps.
- Click the Available Apps tab.
- Search for the BlueApp, and then click the tile.
- Click the Actions tab to display information for the supported actions.
- Click the History tab to display information about the executed orchestration actions.
Launch Actions from USM Anywhere
If you want to apply an action to similar events that occur in the future, you can also create orchestration rules directly from an action applied to an alarm, event, or vulnerability. When reviewing an alarm originated from a Cisco Secure Firewall ASA event, should you conclude that the Cisco Secure Firewall ASA user account has been compromised, you can launch an action to inactivate the Cisco Secure Firewall ASA user account associated with that alarm. If you want to apply the action to similar alarms that occur in the future, you can create an orchestration rule after you apply the action. To launch a Cisco Secure Firewall ASA response action- Go to Activity > Alarms, Activity > Events, or Environment > Vulnerabilities.
- Click the alarm, event, or vulnerability to open the details.
- Click Select Action.
- In the Select Action dialog box, select Run Cisco Secure Firewall ASA Action and enter the Cisco Secure Firewall ASA Group Name and Group Description. Additional fields will be populated based on the action you’ve selected. Fill out the necessary fields for the app action. Additionally, you can choose to clear the active IP connections by selecting the Clear Active Connections checkbox.
- Click Run. After USM Anywhere initiates the action for the alarm, it displays a confirmation dialog box.