wazuh-documentation
wazuh-documentation copied to clipboard
How to achieve correlation of rules tutorial
Correlation of Rules is a very common topic among Community Channels.
How to trigger one rule after two other rules were triggered.
We all know this is not an out of the box feature and yet can be performed with some workarounds using timeframe and groups.
For this reason, we propose a draft tutorial to achieve this based on a simple example.
The provided draft was written and tested as a generic example based on a community request.
Please evaluate if this can be part of documentation, blog entry or any entry that can be found after an initial search regarding correlation. Also please double check with Core team if this provides a working scenario without errors.
Reference here : .md file Regards,