Where is the correlation_id value used?

randytangco
Mega Guru

Hello..   I have been trying to understand where is the correlation_id field is used in the security operations application when managing an incoming security event.

OOB, I think the SIEM (Splunk) sends a snsecevent message to SN.   I get to see the correlation_id field in the additional field of the event table.

However, I am not able to find in the system where is that used for managing the creation of alerts for de-duplication purposes.     Is there a place to check how it is used?

6 REPLIES 6

sachin_namjoshi
Kilo Patron
Kilo Patron

sachin.chinchkar..   Thank you for your reply.   I am actually looking for the specific place in the security operations application where that field is used in managing duplicate events coming in from Splunk for example.


You can check related objects of security application by finding scripts contain corelation id.



Regards,


Sachin


sachin.chinchkar.   Thank you.   Where do I start in the platform for the related objects?