To create a Correlation Rule:
Open the Correlation Rules window and select a folder from the Folder drop-down list to which this rule will be added.
Click Add button located on the top left corner of the screen.
The Rule Wizard opens. Select one of the following rule types and follow the steps for that particular rule type:
Simple
Composite
Aggregate
Sequence
Custom/Freeform
Define the update criteria for the rule. If you select "Continue to perform actions every time this rule fires", the rule will fire every time the criteria is met. If you select "Do not perform actions every time this rule fires for the next (t) time," the events will fire only once as per user-defined time period. All the other events that match the correlation rule within the specified time will be grouped together with this correlated event. This user-defined time period may be a certain number of seconds, minutes, or hours.
Click Next.
Enter the rule name. The syntax of the rule is checked at the time it is created.
Under Namespace, select a correlation rule folder in which to store the rule.
Type the description of the rule.
Click Next. The rule is created and displays in the Correlation Rules window.
Select Yes if you want to create another rule or No if you do not want to create another rule. Click Next.
The rule types and the steps to create them are described below.