Create a correlation rule - Create new correlation rules from either the Correlation Rules page or when building a query in XQL Search, or import a many correlation rules from a file. - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Create new correlation rules from either the Correlation Rules page or when building a query in XQL Search, or import a many correlation rules from a file.

Notice

Correlation rules require a Cortex XDR Pro license.

You can create a new correlation rule from either the Threat ManagementDetection RulesCorrelation Rules page or when building a query in XQL Search. You can also import a number of correlation rules.

When setting up correlation rules, you have the following capabilities:

  • Define when the correlation rule runs.

  • Define whether issues generated by the correlation rule are suppressed by a duration time and a field.

  • Set the resulting action for the correlation rule, which includes any of the following:

    • Generate an issue: You can also define the issue settings, which include the Issues Field Mapping for incident enrichment, Issue Severity, MITRE Attack Tactics and Techniques, and other issue settings.

    • Save data to a dataset: Use this option to test and fine-tune new rules before initiating issues and applying correlation of correlation use cases.

    • Add data to a lookup dataset

    • Remove data from a lookup dataset

Note

To ensure your correlation rules raise issues efficiently and do not overcrowd your Issues table, Cortex XDR automatically disables correlation rules that reach 5000 or more hits over a 24-hour period.