2021-03-05 12:16 AM - edited 2021-03-05 12:26 AM
ESA question :
I have 2 events coming in - 2 events are from different device type with different contents. both arriving within say 5-10 Minutes.
I need to create a rule that matches 5-10 minutes previous event from one device type with the real time event coming from other device type.
Any suggestions will be helpful, Thanks in advance!
2021-03-07 05:57 AM
you can set the time in the rule for 15 min or more, and then set the first rule and use "followed by" the second rule,
but this could affect the Memory on the ESA server
2021-03-08 07:19 AM
You can try with 'create window' in Advanced EPL