The custom or freeform rule option is the most powerful option for creating a correlation rule. This allows the user to create any of the previous types of rules by typing the RuleLG correlation rule language directly into the Correlation Rule Wizard.
Freeform rules are the only way to include certain functionality in a correlation rule. Freeform rules give you the ability to do the following:
Nest operations by using parentheses to specify order of operations
Use the inlist operator to refer to a dynamic list
Use the isnull operator to refer to unpopulated fields
Use the w. prefix for a field name in the window operation to compare an incoming event’s value to a set of previous events
HINT:You can select the functions, operators, and meta tags from the drop-down list selection. Type e. or w. in the Correlation Rule section to view the drop-down lists.
To create a custom or freeform rule:
Open the Correlation Rule Manager window and select a folder from the
drop-down list to which this rule is added.Click the
button located on the top left corner of the screen. The Correlation Rule window displays. Select .In the Custom/Freeform Rule window, write the condition for the rule and click
to test the validity of the rule.After validation of the rule, click
. The Update Criteria window displays.Update the criteria for the rule to fire and click
.Provide a name for this rule. You have an option to modify the rule folder.
Provide rule description and click Next.
You have an option to create another rule from this wizard. Select your option and click
.For trademark and copyright information, see Legal Notices.