A sequence rule is comprised of two or more subrules that must be triggered in a specific order within the defined time frame. Sequence rules have an optional
field, which can be any populated field from the events.NOTE:When a subrule is used to create a sequence rule, a copy of the subrule is added to the sequence rule’s definition. Because a copy is added, changes to the original subrule do not affect the sequence rule.
To create a sequence rule:
Open the Correlation Rule Manager window and select a folder from the
drop-down list to which this rule is added.Click the
button located on the top left corner of the screen. The Correlation Rule window displays. Select .In the Sequence Rule window, click the
button to select a sub rule to create a sequence rule. The Add Rule window displays.Select a rule and click
.Set parameters for the rule to fire. To group event tags according to the attributes, click
. The Attribute List window displays.Select the attribute you want, then You can preview the rule in RuleLg preview box.
Click
.The Update Criteria window displays.Update criteria for the rule to fire and click
.Provide a name for this rule. You have an option to modify the rule folder.
Provide rule description and click
.You have an option to create another rule from this wizard. Select your option and click
.For trademark and copyright information, see Legal Notices.