For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 3.x

Manage correlation rules

View and manage your correlation rules

View and manage your correlation rules in Detection RulesCorrelation Rules. To manage a Correlation Rule, right-click the Correlation Rule and select an action.

You can also monitor your correlation rule executions with the correlations_auditing data set. For more information, see Monitor correlation rules.

Right-click actions for managing correlation rules
  • View related alerts: View the alerts generated by this correlation rule in the Alerts page. You can Show alerts in new tab or Show alerts in same tab.

  • Open in XQL: View the XQL results for the correlation rule in XQL Search. You can Show results in new tab or Show results in same tab.

  • Execute Rule: Run the rule now without waiting for the scheduled time.

  • Preview Rule: View the rule before it's executed.

  • Save as new: Duplicate the correlation rule and save it as a new correlation rule.

  • Export: Select one or more rules to export to a JSON file.

  • Disable the selected correlation rule. This option is only available on an active rule.

  • Enable the selected correlation rule. This option is only available on an inactive rule.

  • Edit Rule: Edit the rule parameters configured in the Edit Correlation Rule editor.

  • Delete the correlation rule.

  • Copy entire row to copy the text from all the fields in a row of a correlation rule.

  • Show rows with ‘<field value>’ to filter the correlation rules list to only display the correlation rules with a specific field value that you select in the table. On certain fields that are null, this option does not display.

  • Hide rows with ‘<Rule Description>’: Filter the correlation rules list to hide the correlation cules with a specific field value that you select in the table. On certain fields that are null, this option does not display.

Last updated

Was this helpful?