Correlation Rule Types

Correlation rules may be defined in the Correlation Rule Wizard by walking through the wizard or by choosing the Custom/Freeform option to write the rule in the proprietary RuleLG language. All rule definitions are stored in the database in RuleLG.

Correlation rules may be defined based on any populated event field.

NOTE: While creating a Rule, you may add a dynamic list to it. For more information, refer to Associating Dynamic List with Correlation Rule.