Composite Rule
A composite rule is comprised of two or more subrules. A composite rule can be defined so that all
or a specified number of the subrules must fire within the defined time frame. Composite rules have
an optional group by field, which can be any populated field from the events.
NOTE: When a subrule is used to create a composite rule, a copy of the subrule is added to the
composite rule's definition. Because a copy is added, changes to the original subrule do not affect
the composite rule.
To create a composite rule:
1 Open the Correlation Rule Manager window and select a folder from the drop-down list to
which this rule is added.
2 Click the Add button located on the top left corner of the screen. The Correlation Rule window
displays. Select Composite Rule.
3 In the Composite Rule window, click Add Rule to select sub rules to create a composite rule.
The Add Rule window displays.
4 Select a rule or a set of rules nd click OK.
5 Set parameters for the rule to fire.
6 To group event tags according to the attributes, click Add/Edit. The Attribute window displays.
7 Select the attribute you want, then preview the rule in RuleLg preview box.
8 Click Next.The Update Criteria window displays.
9 Update criteria for the rule to fire and click Next.
10 Provide a name for this rule. You have an option to modify the rule folder.
92
Sentinel 6.1 Rapid Deployment User Guide