Skip to content
  • There are no suggestions because the search field is empty.

Rules containing a group-by statement with a multi-valued meta fail in RSA Security Analytics 10.6

Issue

Rules containing a group-by statement with a multi-valued meta (such as alias_host) fails.

Steps to Reproduce
  1. Create an ESA Rule with a single statement, having a multi-valued meta field such as alias_host in the condition, and group by that meta value.
  2. Inject matching events and attached events.  The rule will not trigger.

Resolution

This issue is resolved in Security Analytics 10.6.1.


Product Details

RSA Product Set: Security Analytics
RSA Product/Service Type: Event Stream Analysis (ESA)
RSA Version/Condition: 10.6
Platform: CentOS
O/S Version: EL6

Approval Reviewer Queue

RSA NetWitness Suite Approval Queue