Deploying/Undeploying Correlation Rules

Correlation rules can be deployed or undeployed from the Correlation Engine Manager or the Correlation Rule Manager. You can undeploy all rules or a single rule.

To deploy Correlation Rules (in Correlation Engine Manager):

  1. Open the Correlation Engine Manager window.

  2. Highlight and right-click on the engine you want to deploy the rule on and select Deploy Rules.

  3. In the Rules tab, check the rules you want to deploy.

image\ebx_-739195960.gif

NOTE: By default, rules deployed are in enabled state.

  1. In the Actions tab, check the action you want to associate with the rule and click Deploy.

To deploy Correlation Rules (in Correlation Rule Manager):

  1. Open the Correlation Rule Manager window.

  2. Highlight a rule and click Deploy rules link. The Deploy Rule window will display.

image\ebx_1995023119.gif

  1. In the Deploy rule window, select the Engine to deploy the rule from the drop-down list.

  2. [Optional] Select an action or add a new action. If nothing is selected, a Correlated Event with default values will be created.

  3. Click OK.

To Undeploy a Single Rule:

  1. In the Correlation Engine Manager, right-click on the rule and select Undeploy Rule.

  2. Alternatively, in the Correlation Rule Manager, highlight the rule and click Undeploy rule link.

To Undeploy All Correlation Rules:

  1. Open the Correlation Engine Manager window.

  2. Right-click on the Correlation Engine and select Undeploy All Rules.