Deploying and Undeploying Correlation Rules

Correlation rules can be deployed or undeployed from the Correlation Engine Manager or the Correlation Rule Manager. You can undeploy all rules or a single rule.

The rules can be associated with one or more actions. If no action is selected, a default correlated event is generated with the following values:

Table 2 Default Correlated Event Details

Field Name

Default Values

Severity

4

Event Name

Same as the event name for the trigger event

Message

Same as the message for the trigger event

Resource

Correlation

SubResource

<Rule Name>

Other types of actions can be configured in the Action Manager:

To deploy correlation rules in the Correlation Engine Manager:

  1. Open the Correlation Engine Manager window.

  2. Right-click the engine you want to deploy the rule on and select Deploy Rule.

  3. In the Rules tab, select the rule or rules you want to deploy.

  4. In the Actions tab, select the action or actions you want to associate with the rule.

  5. Click Deploy. Rules are deployed in an enabled state.

To deploy correlation rules in the Correlation Rule Manager:

  1. Open the Correlation Rule Manager window.

  2. Select a rule and click the Deploy rules link. The Deploy Rule window displays.

  3. In the Deploy Rule window, select the engine to deploy the rule from the drop-down list.

  4. (Optional) Select an action or add a new action.

    If nothing is selected, a Correlated event with default values is created.

  5. Click Deploy.

To undeploy a single rule:

  1. In the Correlation Engine Manager, right-click the rule and select Undeploy Rule.

    or

    In the Correlation Rule Manager, select the rule and click the Undeploy rule link.

To undeploy all correlation rules:

  1. Open the Correlation Engine Manager window.

  2. Right-click the Correlation engine and select Undeploy All Rules.

For trademark and copyright information, see Legal Notices.