The Advanced EPL Rule tab enables you to define rule criteria with an Event Processing Language (EPL) query.
What do you want to do?
|Role||I want to ...||Show me how|
|Content Expert||Define an Advanced EPL rule.||Add an Advanced EPL Rule|
|Content Expert||Test the Advanced EPL rule logic.||Validate an Advanced EPL Rule|
|Content Expert||See examples of an Advanced EPL Rule.||Example Advanced EPL Rules|
|Content Expert||See best practices for writing Advanced EPL Rules.||ESA Rule Writing Best Practices|
To access the Advanced EPL Rule tab:
The Configure view is displayed with the Rules tab open by default.
The Advanced EPL Rule tab is displayed.
The following figure shows the Advanced EPL Rule tab.
The following table lists the parameters in the Advanced EPL Rule tab.
In the Notifications section, you can choose how to be notified when ESA generates an alert for the rule.
For more information on the alert notifications, see Add Notification Method to a Rule.
The following figure shows the Notifications section.
In the Enrichments section, you can add a data enrichment source to a rule.
For more information on the enrichments, see Add an Enrichment to a Rule.
The following figure shows the Enrichments section.
|To add an enrichment.|
|To delete the selected enrichment.|
|Output||Enrichment source type. Options are: |
|Name of previously configured enrichment source, such as a .CSV filename for an In-Memory Table.|
|ESA Event Stream Meta||ESA meta key whose value will be used as one operand of join condition.|
Enrichment Source Column Name
|Enrichment source column name whose value will be used as the other operand of the join condition.|
In the Test Rule section, you can validate your ESA rule to determine if the rule logic is working as expected before deploying the rule.
|ESA Service||Select the ESA Correlation service to process the rule.|
|Input Data||Enter the input events to test the rule. You can download the events from the Investigate view in JSON format, copy the events, and paste them in this field.|
|Output Data||After you select an ESA Correlation service, input data, and click the Test Rule button, you can view the output of the rule here and verify that the rule is working according to your requirements. You can view the alerts in the output, but this test does not send any alert notifications. If you want to view all of the debug information for the test, include an @Audit(‘stream’) annotation to your rule query.|
The following table describes the test rule output Engine Stats.
|Engine Version||Esper version running on the ESA service|
|Events Offered||Number of events processed by the ESA service since the last service start|
|Offered Rate||The rate that the ESA service processes current events / The maximum rate that the ESA service processed events|
|Runtime Errors||If applicable, this field can contain a link to runtime error messages related to the ESA rule deployment.|
The following table describes the test rule output Rule Stats.
|Deployed||A green checkmark indicates that the rule is deployed on the selected ESA service.|
|Statements Fired||The number of statements that fired the alerts|
|Alerts Fired||The number of alerts generated from the test data|
|Events in Memory||The number of events placed in memory by the rule|
|Memory Usage||The total amount of memory used by the rule|
|CPU %||The percentage of the deployment CPU used by the rule. For example, a deployment with 1 rule shows 100% CPU usage for that rule and a deployment with two equally CPU heavy rules show 50% each.|
|Events Matched||The number of events that matched the rule|
|Alerted Events||If applicable, this field can contain a link to events that caused an alert.|
|Runtime Errors||If applicable, this field can contain a link to runtime error messages related to the rule.|
|Debug Logs||This field contains a link to Esper debug (audit) logs.|
Click Show Syntax to view the EPL syntax of conditions, statements, and debugging parameters. It also provides a warning when the syntax is invalid. For more information, see Rule Syntax Dialog.