Create a correlation rule - Create new correlation rules from either the Correlation Rules page or when building a query in XQL Search, or import a many correlation rules from a file. - Administrator Guide - Cortex CLOUD

Cortex Cloud Runtime Security Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Runtime Security
Creation date
2024-12-24
Last date published
2026-06-10
Category
Administrator Guide
Abstract

Create new correlation rules from either the Correlation Rules page or when building a query in XQL Search, or import a many correlation rules from a file.

You can create a new correlation rule from either the Threat ManagementDetection RulesCorrelation Rules page or when building a query in XQL Search. You can also import a number of correlation rules.

When setting up correlation rules, you have the following capabilities:

  • Define when the correlation rule runs.

  • Define whether issues generated by the correlation rule are suppressed by a duration time and a field.

  • Set the resulting action for the correlation rule, which includes any of the following:

    • Generate an issue: You can also define the issue settings, which include the Issues Field Mapping for incident enrichment, Issue Severity, MITRE Attack Tactics and Techniques, and other issue settings.

    • Save data to a dataset: Use this option to test and fine-tune new rules before initiating issues and applying correlation of correlation use cases.

    • Add data to a lookup dataset

    • Remove data from a lookup dataset