Skip to content

Understanding the UTMStack Correlation Engine #752

Closed Answered by c3s4rfred
jayapradhainfysec asked this question in Q&A
Discussion options

You must be logged in to vote

Hi, @jayapradhainfysec, the correlation engine works as you're saying. The rules aren't triggered for the same use case, like: host, user, ip. When the engine process a use case more than one time within 24h, the logs get grouped in the same rule.

Best regards

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@jayapradhainfysec
Comment options

@c3s4rfred
Comment options

Answer selected by c3s4rfred
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants