Manage correlation rules ↗
View and manage your correlation rules in Threat Management → Detection Rules → Correlations. To manage a Correlation Rule, right-click the Correlation Rule and select an action.
Note\
The maximum number of active scheduled correlations is 1200. This limit applies only to enabled, user-created scheduled correlations. If your organizational needs exceed this limit, please contact your support agent.
You can also monitor your correlation rule executions with the correlations_auditing data set. For more information, see Monitor correlation rules.
Right-click actions for managing correlation rules
- View related issues: View the issues generated by this correlation rule in the Issues page. You can Show issues in new tab or Show issues in same tab.
- Open in XQL: View the XQL results for the correlation rule in XQL Search. You can Show results in new tab or Show results in same tab.
-
Execute Rule: Run the rule now without waiting for the scheduled time.
Note
Execute Rule is not available for real time correlation rules.
- Preview Rule: View the rule before it's executed.
- Save as new: Duplicate the correlation rule and save it as a new correlation rule.
- Export: Select one or more rules to export to a JSON file.
- Disable the selected correlation rule. This option is only available on an active rule.
- Enable the selected correlation rule. This option is only available on an inactive rule.
- Edit Rule: Edit the rule parameters configured in the Edit Correlation Rule editor.
- Delete the correlation rule.
- Copy entire row to copy the text from all the fields in a row of a correlation rule.
- Show rows with ‘<field value>’ to filter the correlation rules list to only display the correlation rules with a specific field value that you select in the table. On certain fields that are null, this option does not display.
- Hide rows with ‘<Rule Description>’: Filter the correlation rules list to hide the correlation rules with a specific field value that you select in the table. On certain fields that are null, this option does not display.