Creating Rule Sets
You can display existing Rule Sets and create new ones in the Insight Pack editor.
Before you begin
Before you create a Rule set, you must complete the following
prerequisite tasks:
- You must create an Insight Pack Eclipse project.
- You must import the Annotation Query Language (AQL)
rules and save them in the /src-files/extractors/ruleset directory. Important: Ensure that the /src-files/extractors/ruleset directory contains valid Annotation Query Language (AQL) rules. You may write these AQL rules yourself or import them from another project and then edit the rules as necessary.You can add custom annotation logic in two ways. You can add custom .aql files or precompiled AQL modules, which are stored in .tam files, to the rule set directory.
About this task
You use a Rule Set to
define the rules that are used to split or annotate a log record that
belongs to a specified data type.
Note: If you manually edit the metadata\rulesets.json for
a project that you have opened in the Log Analysis Insight Pack Tooling,
any changes you make are not displayed and are overwritten by changes
made within the Tooling.