Create an ESA Rule
This topic describes the steps to create an ESA rule.
To create an ESA Rule
- Go to (CONFIGURE) > Policies.
- In the policies panel, click Content.
- In the left panel, click Content Library.
The available rules are displayed.
-
Click Event Stream Analysis Rule.
-
In the ESA rule panel, click + Create Rule to add an ESA rule.
You can select the Advanced EPL option or Rule Builder option from the dropdown as per your requirement. It navigates to ESA Rules > Rules view.
See the section Add a Rule Builder Rule for more information on creating rules in Rule Builder.
See the section Add an Advanced EPL for more information on creating Advanced EPL.
Note: Analysts must have appropriate permissions to view the ESA rules under (CONFIGURE) > ESA Rules and (CONFIGURE) > Policies pages. For more information, see the Source-server section in the "Role Permissions" topic in the System Security and User Management Guide.
From 12.3 and later, Severity and Notifications list views are added to the Event Stream Analysis Rule section.
The Severity list consists of None, Low, Medium, High, and Critical. You can also view rules filtering these options except for None. For more information on filtering these options, see Filter Content Rules.
Rules with syslog and email notifications can be viewed on the Notifications list of the Event Stream Analysis Rule section.
Previous Page Next Page