Custom or Freeform Correlation Rules

The custom or freeform rule option is the most powerful option for creating a correlation rule. This allows the user to create any of the previous types of rules by typing the RuleLG correlation rule language directly into the Correlation Rule Wizard.

TIP:

You can select the Functions, Operators and Meta-Tags from the drop-down list selection. Enter e. or w. in the Correlation Rule section to view the drop-down lists.

To create a custom or freeform rule:

  1. Open the Correlation Rules window and select a folder from the Folder drop-down list to which this rule will be added.

  2. Click the Add button located on the top left corner of the screen. The Correlation Rule window will display. Select Custom/Freeform Rule.

image\ebx_90806592.gif

  1. In the Custom/Freeform Rule window, write the condition for the rule and click Validate to test the validity of the rule.

  2. On successful validation of the rule, click Next, the Update Criteria window will display.

Update the criteria for the rule to fire and click Next.

  1. Enter a name to this rule. You have an option to modify the rule folder.

  2. Enter rule description and click Next.

  3. You have an option to create another rule from this wizard. Select your option and click Next.