I get the following error while deploying the rule. I've check the syntax and it says rule is valid.
ESA was unable to deploy one or more rules, and these rules were disabled. Common issues include: missing metadata, invalid rule syntax, and unavailable external connections at the time of deployment.
Following is the rule logic used. I'm not sure what the problem is.
This basic template is a placeholder for defining basic EPL content that can be
installed and executed in ESA. The sample below is the minimum that would be
required to get started.
Module debug section. If this is empty then debugging is off.
/* EPL section. If there is no text here it means there were no statements. */
SELECT * FROM Event
/* Statement: Repeated Uniform Bytes to Domains */
(domain_dst IS NOT NULL
AND bytes_src IS NOT NULL)
.win:time_length_batch(5 Minutes, 100)
GROUP BY bytes_src
HAVING COUNT(*) >= 100;