ā2021-03-05
12:16 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
ESA Rule Creation
ESA question :
I have 2 events coming in - 2 events are from different device type with different contents. both arriving within say 5-10 Minutes.
I need to create a rule that matches 5-10 minutes previous event from one device type with the real time event coming from other device type.
Any suggestions will be helpful, Thanks in advance!
2 Replies
ā2021-03-07
05:57 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
you can set the time in the rule for 15 min or more, and then set the first rule and use "followed by" the second rule,
but this could affect the Memory on the ESA server
ā2021-03-08
07:19 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
You can try with 'create window' in Advanced EPL
