Skip to content
  • There are no suggestions because the search field is empty.

Advanced EPL Rule Tab

Advanced EPL Rule TabAdvanced EPL Rule Tab

The Advanced EPL Rule tab enables you to define rule criteria with an Event Processing Language (EPL) query.

What do you want to do?What do you want to do?

Related TopicsRelated Topics

Quick LookQuick Look

To access the Advanced EPL Rule tab:

  1. Go to netwitness_configureicon_24x21.png (Configure) > ESA Rules.

    The Configure view is displayed with the Rules tab open by default.

  2. In the Rule Library toolbar, select netwitness_ic-addlist.png > Advanced EPL.

    The Advanced EPL Rule tab is displayed.

The following figure shows the Advanced EPL Rule tab.

netwitness_121_adveplbldr_1122_768x435.png

The following figure shows the Advanced EPL Rule tab scrolled down with the Test Rule section in view.
netwitness_121_adveplbldrtest_1122_768x435.png

The following table lists the parameters in the Advanced EPL Rule tab.

Notifications SectionNotifications Section

In the Notifications section, you can choose how to be notified when ESA generates an alert for the rule.

For more information on the alert notifications, see Add Notification Method to a Rule.

The following figure shows the Notifications section.

netwitness_notificationadded_672x95.png

Enrichments SectionEnrichments Section

In the Enrichments section, you can add a data enrichment source to a rule.

For more information on the enrichments, see Add an Enrichment to a Rule.
The following figure shows the Enrichments section.
netwitness_ruleenrsec_672x94.png

Test Rule SectionTest Rule Section

Note: The Test Rule section is available in NetWitness Platform 11.5 and later.

In the Test Rule section, you can validate your ESA rule to determine if the rule logic is working as expected before deploying the rule.

netwitness_advrb_testrulesection_576x474.png

The following table describes the test rule output Engine Stats.

The following table describes the test rule output Rule Stats.

SyntaxSyntax

Click Show Syntax to view the EPL syntax of conditions, statements, and debugging parameters. It also provides a warning when the syntax is invalid. For more information, see Rule Syntax Dialog.