Standard correlation rules

Standard correlation rules are used to identify complex patterns in processed events.

The search for patterns is conducted by using containers

The correlation rule resource window contains the following configuration tabs:

General tab

Selectors tab

There can be multiple selectors in the standard resource kind. You can add selectors by clicking the Add selector button and can remove them by clicking the Delete selector button. Selectors can be moved by using the DragIcon button.

For each selector the following parameters are available:

If more than one selector is added to the correlation rule resource, the Join filter settings block becomes available. This filter is used to compare the fields of different events. The Join filter is configured by using the Filter drop-down list as described above.

Actions tab

There can be multiple triggers in a standard type of resource.

Every trigger is represented as a group of settings with the following parameters available:

Page top