• Output Sets

  • If any past event evaluates to true with the current event for the simple boolean expression, the output set is the incoming event plus all matching past events.

  • If no events in the window match the current event for the simple boolean expression, the output set is empty.

  • If a window is the last or only operation of a correlation rule, then the output set of the window is used to construct a correlated event (the correlated events being the window operation output set of events with the current event first).