- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
@RSAAlert in Advanced EPL
Hi everyone, Did anyone have information about the RSAAlert parameters for Advanced EPL rules? Especially the "oneInSeconds" param means and wich are it boundaries?
Thanks in advance
- Tags:
- advanced epl
- Community Thread
- Discussion
- EPL
- ESA
- Forum Thread
- NetWitness
- NW
- NWP
- RSA NetWitness
- RSA NetWitness Platform
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Maximiliano,
@RSAAlert is an annotation that's required to generate alert notifications.
oneInSecords is a legacy annotation and only applies to SA 10.3. It used to be Security Analytics’ notification suppression.
Please find more information on @RSAAlert from https://community.rsa.com/docs/DOC-80047.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thank you very much James! I have read the article before, but it doesn't mention about the oneInSeconds parameters. I wonder if there is any way to suppress an alert output beyond the 100 minutes of the notification box restriction.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Maxi, have you tried the "output first every X hours" on the advanced EPL Rule? You can combine it with the identifiers attribute on the @RSAAlert.
Abrazo.
