This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Knowledge Base Archive
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • NetWitness Knowledge Base Archive
  • Newly created Incident Management (IM) aggregation rules for ESA alerts are processing old alerts in...
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content

Newly created Incident Management (IM) aggregation rules for ESA alerts are processing old alerts in RSA Security Analytics

Article Number

000032434

Applies To

RSA Product Set: Security Analytics
RSA Product/Service Type: Incident Management, Event Stream Analysis (ESA), Security Analytics UI
RSA Version/Condition: 10.5.x, 11.X
Platform: CentOS
O/S Version: EL6

Issue

Newly created Incident Management (IM) aggregation rules for ESA alerts are processing old alerts.
For instance, if an aggregation rule is created today, alerts in Incident Management Alerts Or SecOps Incidents contain alerts going as far back as a couple of months.

Cause

By default, aggregation rules will look up all the alerts in the alert database.

Resolution

In the aggregation rule, there is an option to select alerts based on "Date Created". 
Add a condition for "Date Created" that is greater than or equal to the date desired in the aggregation rule itself.

Image descriptionImage description

​In 11.X version,

Image descriptionImage description


If Query Mode is Advanced for Incident rules, please use below syntax for Incident creation greater than the required date.

{"$and":[{"alert.source":"Event Stream Analysis"},{"alert.name":{"$in":["rule1", "rule2"]}},{"alert.timestamp":{"$gt":{"$date":"2021-12-30T12:00:30Z"}}}]}
Tags (58)
  • 11.x
  • Appliance
  • Broker
  • Broker Appliance
  • Config
  • Configuration
  • Configure
  • Configuring
  • Core Appliance
  • Customer Support Article
  • ESA
  • ESA Appliance
  • ESA Service
  • Event Stream Analysis
  • Head Unit
  • HeadUnit
  • Helpful Hints
  • How To
  • Implementation
  • Implementing
  • Informational
  • Instructions
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • NetWitness
  • NetWitness Appliance
  • NetWitness Broker
  • NetWitness Head Unit
  • NetWitness Platform
  • NetWitness Server
  • NetWitness UI
  • NW
  • NW Appliance
  • NwBroker
  • Process Steps
  • RSA NetWitness
  • RSA NetWitness Platform
  • RSA NetWitness UI
  • RSA Security Analytics
  • RSA Security Analytics UI
  • Security Analytics
  • Security Analytics Server
  • Security Analytics UI
  • Set Up
  • Setup
  • SIEM
  • Tip &amp Tricks
  • Tips and Tricks
  • Tutorial
  • UI
  • UI Server
  • User Interface
  • Version 11
  • Version 11.x
  • Walk Through
  • Walkthrough
  • Web Interface
0 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2022-01-24 05:37 AM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.