2024-06-03 10:23 PM
I'm trying to create an ESA Alert that will create an alert for any events that match a certain criteria within a 30 second window.
I'm not entirely sure how to achieve this with ESA.
2024-06-24 11:29 AM
I believe the rule builder gives you the option for setting up time in minutes. As such, you might be able to use the rule builder wizard to build out your rule, set it for 1 minute, and see if you get the results you are expecting. If that works, then you should be able to look at the underlying rule syntax to see how it is written and modify it for the 30 seconds that you want instead of 60 seconds.
I'm not real savvy with ESA rule creation myself, but the logic seems sound.