> For the complete documentation index, see [llms.txt](https://documentation.ocsinventory-ng.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://documentation.ocsinventory-ng.org/administrator-docs/server-setup/configuration/advanced/managing-rules.md).

# Managing Rules

The OCS Rule engine allows automatic actions on objects when they match a certain criteria.

## Triggers

The server uses a predefined set of **triggers** that determine **when** the rules are evaluated and the **scope** of the data considered:

* **Base inventory received:** triggers when a base inventory is created or updated. The scope is limited to the fields defined in the base inventory.\
  See [Inventory and Templates](/user-docs/asset-management/inventory-and-templates.md#base-inventory) for more details.
* **User login:** triggers when a user logs in through any authentication method. The scope is limited to user-related fields.
* **Network device inventory received:** similar to the **Base inventory received** trigger, but applied to IPDiscover devices.

## **Default Rules**

Out of the box, OCS provides six predefined rules, evaluated against the **OS Name** or **Agent** field of the base inventory and used to assign Templates automatically:

{% columns %}
{% column width="33.33333333333333%" %}

<p align="center"><strong>Field evaluated</strong></p>

<p align="center">OS Name</p>

<p align="center">OS Name</p>

<p align="center">OS Name</p>

<p align="center">OS Name</p>

<p align="center">Agent</p>

<p align="center">OS Name</p>
{% endcolumn %}

{% column width="41.66666666666667%" %}

<p align="center"><strong>Value(s) expected</strong></p>

<p align="center">Windows</p>

<p align="center">Ubuntu, Debian</p>

<p align="center">Redhat, Centos, Alma, Rocky</p>

<p align="center">Mac</p>

<p align="center">OCS-NG</p>

<p align="center">SNMP</p>
{% endcolumn %}

{% column width="24.999999999999986%" %}

<p align="center"><strong>Template</strong></p>

<p align="center">Windows</p>

<p align="center">Debian based</p>

<p align="center">RHEL based</p>

<p align="center">macOS</p>

<p align="center">Legacy</p>

<p align="center">Generic SNMP</p>
{% endcolumn %}
{% endcolumns %}

<figure><img src="https://461838061-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtjrEC8kt8LJiJYFBs5CS%2Fuploads%2FYuk2h2HWBmXCDtXcvlwF%2Fimage.png?alt=media&amp;token=754173f5-4147-41a4-aa35-06669a34b03c" alt="Rules general view"><figcaption><p>Rules general view</p></figcaption></figure>

## Rule evaluation order

Rules are evaluated **per trigger**, by execution priority order. Actions inside a rule are also evaluated by priority.\
Rules have a **break on first match** option: if enabled and the rule matches, its actions are executed first, then evaluation stops for remaining rules of that trigger.

If multiple executed rules/actions write the same field, the **last executed write wins** which is why priority order and break on first match are important.

### To change the execution order:

{% stepper %}
{% step %}
Navigate to **Configuration** **→** **Inventory → Rules.**
{% endstep %}

{% step %}
Locate the **handle**.

Find the **drag-and-drop handle** on the left side of the Actions table for each entry.
{% endstep %}

{% step %}
**Reposition** the row.

Drag the handle to move the row to your desired order.

The table will automatically update to reflect the new order.
{% endstep %}
{% endstepper %}

## Creating a rule

{% stepper %}
{% step %}
Navigate to **Configuration** **→** **Inventory → Rules.**&#x20;
{% endstep %}

{% step %}
Click the **Add a rule** button (top right of the table).
{% endstep %}

{% step %}
Complete the form.

* Name
* [#triggers](#triggers "mention")
* **Enabled** switch
* **Break on first match** switch
  {% endstep %}

{% step %}
Click **Add**.

The new rule will appear in the list.
{% endstep %}

{% step %}
**Locate** the newly created rule, then click the **gear icon** in the Actions column.

By default, you’ll be directed to the **Criteria** tab, where you can define the conditions a device or user must match.
{% endstep %}

{% step %}
Define a criteria and click **Save**.
{% endstep %}

{% step %}
Switch to the **Actions** tab.
{% endstep %}

{% step %}
Specify the actions to be performed on matching objects, then click **Save.**
{% endstep %}
{% endstepper %}

{% tabs %}
{% tab title="Generic rule" %}
{% stepper %}
{% step %}
Navigate to **Configuration** **→** **Inventory → Rules.**&#x20;
{% endstep %}

{% step %}
Click the **Add a rule** button (top right of the table).
{% endstep %}

{% step %}
Complete the form.

* Name
* [#triggers](#triggers "mention")
* **Enabled** switch
  {% endstep %}

{% step %}
Click **Add**.

The new rule will appear in the list.
{% endstep %}

{% step %}
**Locate** the newly created rule, then click the **gear icon** in the Actions column.

By default, you’ll be directed to the **Criteria** tab, where you can define the conditions a device or user must match.
{% endstep %}

{% step %}
Define a criteria and click **Save**.
{% endstep %}

{% step %}
Switch to the **Actions** tab.
{% endstep %}

{% step %}
Specify the actions to be performed on matching objects, then click **Save.**
{% endstep %}
{% endstepper %}
{% endtab %}

{% tab title="Authentication rule" %}
Authentication rules can assign users to groups when they log in.

These rules can evaluate:

* The authentication method used by the user
* The authentication configuration used during login
* Authentication metadata returned by the identity provider

{% hint style="info" %}
Authentication metadata is specific to providers. Use `.` to navigate nested values.

Examples:

* **LDAP:** `memberOf`, `dn`, `attributes`
* **OIDC:** `claims.sub`, `claims.email`, `claims.groups`
* **CAS:** `attributes.givenName`, `attributes.roles`, `attributes.department`
  {% endhint %}

{% stepper %}
{% step %}
Navigate to **Configuration** **→** **Inventory → Rules.**
{% endstep %}

{% step %}
Click the **Add a rule** button (top right of the table).
{% endstep %}

{% step %}
Complete the form.

* Name
* Choose **User login** as the [#triggers](#triggers "mention")
* Enable the rule
  {% endstep %}

{% step %}
Click **Add**.

The new rule will appear in the list.
{% endstep %}

{% step %}
**Locate** the newly created rule, then click the **gear icon** in the Actions column.

By default, you’ll be directed to the **Criteria** tab, where you can define the conditions a user must match.
{% endstep %}

{% step %}
For this example, assign users authenticated with **OIDC** based on the `custom_group` attribute.

We check that `claims.custom_group` contains `asset-management`.

<figure><img src="https://461838061-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtjrEC8kt8LJiJYFBs5CS%2Fuploads%2FbKF21cq6c04zyTrNr4Nh%2Fimage.png?alt=media&amp;token=9defd70a-12b7-4f0d-a1b5-86631d0aad2c" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
If several LDAP configurations are enabled, you can choose which one the rule applies to. Local, OIDC, and CAS only allow one active configuration.
{% endhint %}
{% endstep %}

{% step %}
Switch to the **Actions** tab.
{% endstep %}

{% step %}
Specify the actions to be performed on matching objects, then click **Save.**
{% endstep %}
{% endstepper %}
{% endtab %}
{% endtabs %}

## Updating a rule

{% stepper %}
{% step %}
Navigate to **Configuration** **→** **Inventory → Rules.**
{% endstep %}

{% step %}
Locate the rule you want to modify and click the **gear icon** in the Actions column.

<details>

<summary>Modifying the criteria</summary>

On the default tab (**Criteria**), update or add new conditions as needed.

</details>

<details>

<summary>Modifying the action</summary>

Switch to the **Actions** tab, then update or add an action as needed.

</details>
{% endstep %}

{% step %}
Click **Save**.

Updating a rule immediately affects all future inventory or login events matching its criteria.
{% endstep %}
{% endstepper %}

### Enabling or disabling a rule

{% stepper %}
{% step %}
Navigate to **Configuration** **→** **Inventory → Rules.**
{% endstep %}

{% step %}
Locate the rule you want to modify and click the **pencil** **icon** in the Actions column.
{% endstep %}

{% step %}
Use the **switch** to enable or disable the rule.
{% endstep %}

{% step %}
Click **Save**.

{% hint style="info" %}
Disabling a rule prevents it from being executed during inventory or login events until it is re-enabled.
{% endhint %}
{% endstep %}
{% endstepper %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://documentation.ocsinventory-ng.org/administrator-docs/server-setup/configuration/advanced/managing-rules.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
