Create a correlation rule - Create new correlation rules from either the Correlation Rules page or when building a query in XQL Search, or import a many correlation rules from a file. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-16
Category
Administrator Guide
Abstract

Create new correlation rules from either the Correlation Rules page or when building a query in XQL Search, or import a many correlation rules from a file.

Prerequisite

To enable pivots from issues to a third-party source system, ensure that you know the dataset field name that contains the URL of the source system. Some vendors already provide this URL as part of their API, and you can find it in the third-party product dataset. If there is no URL, you cannot enable this feature.

You can create a new correlation rule from either the Threat ManagementDetection RulesCorrelation Rules page or when building a query in XQL Search. You can also import a number of correlation rules.

When setting up correlation rules, you have the following capabilities:

  • Specify whether the correlation rule is Scheduled, or scans the data in Real Time, as it’s ingested.

  • Define when the correlation rule runs.

  • Define whether issues generated by the correlation rule are suppressed by a duration time and a field.

  • Set the resulting action for the correlation rule, which includes any of the following:

    • Generate an issue: You can also define the issue settings, which include the Issues Field Mapping for incident enrichment, Issue domain, Issue Severity, MITRE Attack Tactics and Techniques, and other issue settings.

    • Save data to a dataset: Use this option to test and fine-tune new rules before initiating issues and applying correlation of correlation use cases.

    • Add data to a lookup dataset

    • Remove data from a lookup dataset

Note

  • When creating a Real Time Correlation Rule, you can only generate an issue as the resulting action for the Correlation Rule. All other options are disabled.

  • To ensure your Correlation rules generate issues efficiently and do not overcrowd your Issues table, Cortex XSIAM automatically disables Correlation rules that reach 5000 or more hits over a 24-hour period.