The Advanced EPL Rule tab enables you to define rule criteria with an Event Processing Language (EPL) query.
What do you want to do?
|Role||I want to ...||Show me how|
|Content Expert|| |
Define an Advanced EPL rule.
|Content Expert|| |
See examples of an Advanced EPL Rule.
|Example Advanced EPL Rules|
See best practices for writing Advanced EPL Rules.
To access the Advanced EPL Rule tab:
Go to Configure > ESA Rules.
The Configure view is displayed with the Rules tab open by default.
The Advanced EPL Rule tab is displayed.
Below is a screen shot of the Advanced EPL Rule tab.
The following table lists the parameters in the Advanced EPL Rule tab.
|Rule Name||Purpose of the ESA rule.|
|Description||Summary of what the ESA rule detects.|
|Trial Rule||Deployment mode to see if the rule runs efficiently.|
|Alert||(This option applies to version 11.3 and Later.) When selected, the alert is sent to Respond. If the checkbox is cleared, an alert will not be sent to Respond.|
To turn alerts on or off for ALL rules, see the ESA Configuration Guide.
|Severity||Threat level of alert triggered by the rule.|
|Query||EPL query that defines rule criteria.|
In the Notifications section, you can choose how to be notified when ESA generates an alert for the rule.
For more information on the alert notifications, see Add Notification Method to a Rule.
The following figure shows the Notifications section.
In the Enrichments section, you can add a data enrichment source to a rule.
For more information on the enrichments, see Add an Enrichment to a Rule.
The following figure shows the Enrichments section.
To add an enrichment.
|To delete the selected enrichment.|
Enrichment source type. Options are:
|Name of previously configured enrichment source, such as a .CSV filename for an In-Memory Table.|
ESA Event Stream Meta
ESA meta key whose value will be used as one operand of join condition.
Enrichment Source Column Name
|Enrichment source column name whose value will be used as the other operand of the join condition.|
Click Show Syntax to view the EPL syntax of conditions, statements, and debugging parameters. It also provides a warning when the syntax is invalid. For more information, see Rule Syntax Dialog.