Specifying Rule Conditions
Purpose:
To find events that match the rule condition statements; and if matching events are found:
- Trigger the rule action(s).
- Generate a correlation event.
Definition of terms:
- Base events are the events that match the rule's conditions. They are also called correlated events.
- Correlation event is a system-generated audit event that caused the rule to trigger.
Topics include: