AnsweredAssumed Answered

Creating a simple ESA rule

Question asked by Jeremy Kerwin on Nov 24, 2019
Latest reply on Nov 26, 2019 by James Moon

Sorry for such a simple questioni

I had a simple ESA rule that was working prior to upgrading to 11.3.1.1. but now it's not triggering anymore and gives an error about in incorrect use of an OR clause or something to that effect

The rule basically goes.

 

If alert contains 'panda' OR 'bear' OR 'spider' AND IP address is not 128.0.0.1 then generate an alert and notify by email.

 

Rather than trying to troubleshoot the old rule, I'm happy to just create a new, working one. Could someone help me in how this would look in the rule builder?

Thanks. 

Outcomes