Help Center> Cloud Bastion Host> User Guide> Policy> Command Rules> Querying and Editing a Command Rule
Updated on 2022-11-30 GMT+08:00

Querying and Editing a Command Rule

This topic describes how to view and edit a command rule. You can view and edit the rule configurations, including the basic settings, related passwords, and related command sets. You can also edit the users, user groups, accounts, account groups related to the rule.

  • A modified database rule takes effect the instant its status changes to Enabled.
  • If related users have logged in to resources before the modification, those users need to log out and log in again for the modified database rule to take effect.

Prerequisites

You have obtained the permissions to manage the Cmd Rules module.

Querying and Editing Database Rule Configurations

  1. Log in to the CBH system.
  2. Choose Policy > Cmd Rules > Cmd Rules.
  3. Query command rules.

    • Quick search

      Enter a keyword in the search box to quickly query command rules by rule name, user, resource name, host IP address, resource account, command set, command, or parameter.

    • Advanced search

      Enter keywords in the corresponding attribute search boxes to search for database rules in exact mode.

      Figure 1 Advanced search

  4. Click the name of the database rule that you want to edit or click Manage in the row of the rule in the Operation column. The details page of the rule is displayed.

    Figure 2 Viewing rule details

  5. View and edit basic information.

    In the Basic Info area, click Edit. In the displayed dialog box, edit the database rule details.

    You can edit Rule Name, Period of validity, Action, and Time Limit.

    Figure 3 Viewing the basic information

  6. View and edit commands related to the rule.

    • To edit related commands or parameters, click Edit in the Command area and complete modifications in the displayed dialog box.
    • To only delete a related command, click Remove in the row of the related command.
    Figure 4 Viewing related commands

  7. View and edit command sets related to the command rule.

    • To relate a command set to the rule or remove a related command set, click Edit in the Command Set area and complete modifications in the displayed dialog box.
    • To only delete a related command set, click Remove in the row of the related command set.
    Figure 5 Viewing related command sets

  8. View and edit users related to the rule.

    • To relate a user to the rule or remove a related user, click Edit in the Users area and complete modifications in the displayed dialog box.
    • To only remove a related user, click Remove in the row of the related user.
    Figure 6 Viewing related users

  9. View and edit user groups related to the rule.

    • To relate a user group to the rule or remove a related user group, click Edit in the User Group area and complete modifications in the displayed dialog box.
    • To only remove a related user group, click Remove in the row of the related user group.
    Figure 7 Viewing related user groups

  10. View and edit accounts related to the database rule.

    • To relate an account to the rule or remove a related account, click Edit in the Account area and complete modifications in the displayed dialog box.
    • To only remove a related account, click Remove in the row of the related account.
    Figure 8 Viewing related accounts

  11. View and edit account groups related to the rule.

    • To relate an account group to the rule or remove a related account group, click Edit in the Account Group area and complete modifications in the displayed dialog box.
    • To only remove a related account group, click Remove in the row of the related account group.
    Figure 9 Viewing related account groups