Adding Correlations
To add a correlation, do the following:
- In the main menu, click Detection Rules > Correlations.
- Click Add Correlation and specify required fields. For convenience, you can use Veeam correlation rule templates.
An example for the Job Deleted correlation:
Note |
To configure the correlation rule properly, make sure that the dataset name you specify in the query begins with veeam_. For more details, see Configuring Syslog Collectors. |
For more information about correlations, see Cortex XSIAM documentation.