Simple correlation rules are used to define simple sequences of events.
The correlation rule resource window contains the following configuration tabs:
General tab
If correlation rules employing complex logic for pattern detection are not triggered, this may be due to the specific method used to count rule triggers in KUMA. In this case, try to increase the value of Rate limit to 1000000
, for example.
Low
.Selectors tab
In a simple-type resource, there can be only one selector for which the Settings and Local variables tabs are available.
The Settings tab contains settings with the Filter settings block:
On the Local variables tab, use the Add variable button to declare variables that will be used within the limits of this correlation rule.
Actions tab
There can be only one trigger in the simple resource kind: On every event. It is activated every time the selector triggers.
Available parameters of the trigger:
If both check boxes are selected, the correlation rule will be sent for post-processing first and then to the current correlation rule selectors.
Available settings:
The active list entry key depends on the available fields and does not depend on the order in which they are displayed in the KUMA web interface.
The field must not contain special characters or numbers only.
Available types of enrichment: