Creating or Editing an Active Channel

This topic shows how to create active channels manually, from triggered rules, and from filters.

Tip: Press Enter to register edits made in editors and channel columns.

To ensure that ESM registers a change you make to a field in editor and channel columns, press Enter before clicking Apply or OK.

Where: Navigator > Resources > Active Channels

To create or edit an active channel:

  1. Locate an active channel group.

  2. If you are creating an active channel, select New Active Channel.

    If you are editing an active channel, expand the group, right-click an active channel, and choose Edit Active Channel.

  3. Click the Examples button to see how to specify commonly used channel values.

    Entering data in the Common and Assign sections is optional, depending on how your environment is configured. For information about the Common and Assign attributes sections, as well as the read-only attribute fields in Parent Groups and Creation Information, see Common Resource Attribute Fields.

  4. Click the Filter tab to edit the channel's filter condition as described in Creating or Editing a Filter.

    To view the full conditions for the MatchesFilter operator, click the Summary tab and then click the Expand Filter button to display the filter conditions for debugging.

    Note that in this case, the display of the MatchesFilter full logic does not display the sub-filter of the matched filter. Full logic is displayed only for the first level of matched filter conditions.

  5. Click the Sort Fields tab to explicitly set which fields to sort the channel on in grid views, the sort order for those fields, and whether sorting for each field is ascending (A to Z) or descending (Z to A).

  6. Click the Local Variables tab to use ArcSight local variables with the channel's filters.

    Tip: You can create local variables, which are only available to the resource you are creating (in this case, an active channel), or use global variables. For information on creating global variables, see Creating or Editing a Filter and Global Variables.

  7. Optional: To add information in the Notes tab, refer to Using Notes.

  8. Click OK to save the channel and to open and run it in the Viewer panel.

To view results of triggered rules in channels:

See Verifying Rules with Events.

To create active channels from filters: