Improve alert management by enabling users to customize correlation logic order. This feature empowers you to fine-tune correlation methods to their specific needs, enhancing alert prioritization and response
efficiency.
Procedure
-
Navigate to .
-
Search for the property sa_analytics.agg.query.group_logic_order.
Default value is “MIXED,NETWORK_TRAFFIC,PATTERN,GENERALIZED_PATTERNS,TEXTBASE". This is a comma separated list of the grouping types in the order of their execution.
Note: If one of the grouping types is not specified
in the property, it needs to be added manually. Alert correlation rules are trigger-based and applied immediately when an alert is created or
updated, before other grouping algorithms.
-
Use the property sa_analytics.agg.query.group_logic_order to define or modify the order of correlation methods based on your preferences.