Sorry for such a simple questioni
I had a simple ESA rule that was working prior to upgrading to 11.3.1.1. but now it's not triggering anymore and gives an error about in incorrect use of an OR clause or something to that effect
The rule basically goes.
If alert contains 'panda' OR 'bear' OR 'spider' AND IP address is not 128.0.0.1 then generate an alert and notify by email.
Rather than trying to troubleshoot the old rule, I'm happy to just create a new, working one. Could someone help me in how this would look in the rule builder?
Thanks.
Jeremy
You could do something like the following:
I added in your ip after this screen shot was taken
Which would then result in a rule that looks like this in the syntax
Hope that helps
Dave