A composite rule is comprised of 2 or more subrules. A composite rule may be defined so that all or a specified number of the subrules must fire within the defined timeframe. Composite rules have an optional group by field, which may be any populated field from the events.
NOTE: When a subrule is used to create a composite rule, a copy of the subrule is added to the composite rule's definition. Because a copy is added, changes to the original subrule do not affect the composite rule.
.To create a composite rule:
Open the Correlation Rules window and select a folder from the drop-down list to which this rule will be added.
Click the Add button located on the top left corner of the screen. The Correlation Rule window will display. Select Composite Rule.
In Composite Rule window, you may select sub-rules to create a composite rule. To select a sub-rule, click Add Rule button. Add Rule window will display.
Select a rule or a set of rules (hold control on your keyboard to select a set of rules) and click OK.
Set parameters for the rule to fire.
To group event tags according to the attributes, Click Add/Edit. The Attribute Window will display.
Check the attribute as per your requirement. You may preview the rule in RuleLg preview box. Click Next, the Update Criteria window will display.
Update criteria for the rule to fire and click Next.
Enter a name to this rule. You have an option to modify the rule folder.
Enter rule description and click Next.
You have an option to create another rule from this wizard. Select your option and click Next.