Cortex XDR 3.x
Monitor correlation rules
You can monitor your correlation executions with the correlations_auditing dataset.
Cortex XDR audits all correlation executions in the correlations_auditing dataset. The dataset records the query initiation times, end times, retry attempts, failure reasons, and other useful metrics. .
In the correlations_auditing dataset, audit entries are added as follows:
The rule starts executing. This is audited with the status of Initiated or Initiated Manually.
The rule completes successfully. This is audited as Completed.
The rule completes with errors. This is audited as Error.
Last updated
Was this helpful?
