> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/correlation-rule-details.md).

# Correlation rule details

If you are assigned a role that enables Investigation → **Rules** privileges, you can manage all user-defined Correlation Rules from **Threat Management** → **Detection Rules** → **Correlations**.

By default, the **Correlation Rules** page displays all enabled rules. To search for a specific rule, use the filters above the results table to narrow the results. From the **Correlation Rules** page, you can manage existing rules using the right-click pivot menu. You can also import and export rules in JSON format, which can help you to transfer your configurations between environments for onboarding, migration, backup, and sharing. You can bulk export and import multiple rules at a time.

In addition, the **Correlation Rules** page enables you to easily identify and resolve correlation rules errors. The number of errors is indicated at the top of the page in red using the format **\<number> errors found**. You can change the view to only display the correlation rules with errors by selecting **Show Errors Only**. The **LAST EXECUTION** column in the table indicates a correlation rule with an error by displaying the last execution time in a red font and providing a description of the correlation rule error when hovering over the field. The following error messages are displayed in the applicable scenarios.

* Invalid query
* Query timeout
* Dependency correlation did not complete
* Unknown error
* Delayed rule—This rule is running past its scheduled time, which can cause delayed results.
* Dataset does not exist:

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Only an administrator can create and view queries built with an unknown dataset that currently does not exist in Cortex XSIAM .</p></div>

A notification is also displayed in Cortex XSIAM to indicate these correlation rules errors.

{% hint style="info" %}

### Note

For more information on troubleshooting server errors in scheduled correlation rules, Troubleshoot server errors in scheduled correlation rules.
{% endhint %}

<details>

<summary>Correlation rule fields in alphabetical order</summary>

{% hint style="info" %}

### Note

Certain fields are exposed and hidden by default. An asterisk (\*) is beside every field that is exposed by default.
{% endhint %}

| Field                         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ----------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **# OF ISSUES**\*             | The number of issues generated by this rule.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **ALERT CATEGORY**\*          | Type of issue as configured when creating the rule. - Collection - Credential Access - Dropper - Evasion - Execution - Evasive - Exfiltration - File Privilege Manipulation - File Type Obfuscation - Infiltration - Lateral Movement - Persistence - Privilege Escalation - Reconnaissance - Tampering - Other                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **DATASET**\*                 | The text displayed here depends on the resulting action configured for the correlation rule when the rule was created. - **alerts**—When your resulting action for the rule was configured to **Generate issue**. - Dataset name—When your resulting action for the rule was configured to **Save to dataset**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **DESCRIPTION**\*             | The description for the Correlation Rule that was configured when the rule was created.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **DRILL-DOWN QUERY**          | Displays the **Drill-Down Query** that you configured for additional information about the issue for further investigation using Cortex Query Language (XQL) when you created the rule. If you did not configure one, the field is left empty. After configuration, any issue generated for the Correlation Rule has a right-click pivot menu **Open Drilldown Query** option, an **Open drilldown query** link after you investigate any contributing events, and a quick action **Open Drilldown Query** icon (drilldown-icon.png) that is accessible in the **Issues** page, which opens a new browser tab in XQL Search to run this query. If you do not define a **Drill-Down Query**, no right-click menu option, link, or icon is displayed. The **Drill-Down Query Time Frame** can be configured as either. - **Generated Issue**—Uses the time frame of the issue that is generated, which is the first event and last event timestamps for the issue (default option). - **XQL Search**—Uses the time frame from when the Correlation Rule was run in XQL Search. |
| **FAILURE REASON**            | For a Correlation Rule with an error, displays the error message, which can be one of the following. - Invalid query - Query timeout - Dependency correlation did not complete - Unknown error - Delayed rule—This rule is running past its scheduled time, which can cause delayed results. - Dataset does not exist: **Note:** Only an administrator can create and view queries built with an unknown dataset that currently does not exist in Cortex XSIAM.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **INSERTION DATE**            | Date and time when the Correlation Rule was created.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **LAST EXECUTION**\*          | Date and time when the correlation rule was last executed. Indicates a correlation rule with an error by displaying the last execution time in a red font and providing a description of the correlation rule Error when hovering over the field.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **MITRE ATT\&CK TACTIC**\*    | Displays the type of MITRE ATT\&CK tactic the correlation rule is attempting to trigger.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **MITRE ATT\&CK TECHNIQUE**\* | Displays the type of MITRE ATT\&CK technique and sub-technique the correlation rule is attempting to trigger.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **MODIFICATION DATE**\*       | Date and time when the correlation rule was last modified.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **NAME**\*                    | Unique name that describes the rule.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **RULE ID**                   | Unique identification number for the rule.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **SCHEDULE**\*                | Displays the Time Schedule for the frequency of running the XQL Search definition set for the correlation rule when the rule was created. The options displayed are one of the following. - **Every 10 Minutes** - **Every 20 Minutes** - **Every 30 Minutes** - **Hourly** - **Daily** - Displays the Time Schedule as Cron Expression fields.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **SEVERITY**\*                | Correlation rule severity that was defined when the correlation rule was created. Severity levels can be **Informational**, **Low**, **Medium**, **High**, **Critical**, and **Customized**. If a generated issue has severity **Medium** or above, a case is automatically opened. Low severity issues generated by correlation rules are not grouped into cases.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **SOURCE**\*                  | User who created this correlation rule.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **STATUS**                    | Rule status: Enabled or Disabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **SUPPRESSION DURATION**\*    | The duration time for how long to ignore other events that match the issue suppression criteria that was configured when the rule was created. This is required to configure.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **SUPPRESSION FIELDS**\*      | The fields that the issue suppression is based on, which was configured when the rule was created. The fields listed are based on the XQL query result set for the rule. This is optional to configure.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **SUPPRESSION STATUS**\*      | Displays the Suppression Status as either Enabled or Disabled as configured when the rule was created.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **TIME FRAME**\*              | Displays the time frame for running a query, which can be up to 7 days as configured when the rule was created.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **TIMEZONE**                  | Displays the Timezone when the Time Schedule for the frequency of running the XQL Search definition set for the correlation rule is set to run daily or using a cron expression. Otherwise, this field is left empty.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **XQL SEARCH**                | Displays the XQL definition for the correlation rule that was configured in XQL Search when the rule was created.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule/correlation-rule-details.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
