To declare variables, they must be added to a correlator or correlation rule.
To add a global variable to an existing correlator:
The Correlator Installation Wizard opens.
Multiple variables can be added. Added variables can be edited or deleted by using the icon.
A global variable is added to the correlator. It can be queried like an event field by inserting the $ character in front of the variable name. The variable will be used for correlation after restarting the correlator service.
To add a local variable to an existing correlation rule:
The correlation rule settings window opens. The parameters of a correlation rule can also be opened from the correlator to which it was added by proceeding to the Correlation step of the Installation Wizard.
Multiple variables can be added. Added variables can be edited or deleted by using the icon.
For standard correlation rules, repeat this step for each selector in which you want to declare variables.
The local variable is added to the correlation rule. It can be queried like an event field by inserting the $ character in front of the variable name. The variable will be used for correlation after restarting the correlator service.
Added variables can be edited or deleted. If the correlation rule queries an undeclared variable (for example, if its name has been changed), an empty string is returned.
If you change the name of a variable, you will need to manually change the name of this variable in all correlation rules where you have used it.
Page top