2018-09-12 10:11 AM
Hello,
We wanna test rules and alerts with old logs and data. Is that possible? Is there anything that we can put in the EPL rule to retrieve that data?
Regards
2018-09-12 12:32 PM
I don't think that ESA can do that because it doesn't run queries like the RE, but only correlate on-the-fly. If I'm not missing something then your only option is to test this in a lab and re-inject some of the old traffic that you want to use (assuming you are not happy to do that in production).