The Rule Builder tab enables you to define a Rule Builder rule.
What do you want to do?
To access the Rule Builder tab:
Go to CONFIGURE > ESA Rules.
The Rules tab opens by default.
The Rule Builder tab is displayed.
The following figure shows the Rule Builder tab.
The following table lists the parameters in the Rule Builder tab.
The Rule Builder includes the following components:
- Conditions section
- Notifications section
- Enrichments section
In the Conditions section of the Rule Builder tab, you define what the rule detects.
The following figure shows the Conditions section.
The following table lists the parameters of the Conditions section.
In the Notifications section, you can choose how to be notified when ESA generates an alert for the rule.
For more information on the alert notifications, see Add Notification Method to a Rule.
In the Enrichments section, you can add a data enrichment source to a rule.
For more information on the enrichments, see Add an Enrichment to a Rule.
The following figure shows the Enrichments section.
Select the Debug option to print alerts to the ESA logs for troubleshooting.
Click Show Syntax to view the EPL syntax of conditions, statements, and debugging parameters. It also provides a warning when the syntax is invalid. For more information, see Rule Syntax Dialog.