Hi,
I want to create a correlation rule that will collect every single matching log created (by curtain conditions of course) within a 24 hours range (per user).
meaning,
I want that the signature ID to be created only ONCE per source user, and will collect all relevant logs within 24 hours range. any suggestions?
I sat and thought about how to answer your question... I had 3 different answers typed out and they all assumed different assumptions of what your end goal is.
Can you explain what you are trying to do in a more general sense?
Is there something after this you are trying to accomplish?
If you just want the users events over 24 hours, correlation is not what you are looking for. You want to use the reporting functionality with some grouping.
I think you are looking at a report here to start with.
This can easily be accomplished with a grouping (count) on 'source user' where the signature ID is the one you are looking for. I assume you are looking for a windows event? What's the ID. I will see if I can quickly build a report for you. With reports you can even do a distribution over the past days and such to find trends.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA