cancel
Showing results for 
Search instead for 
Did you mean: 

Date driven correlation rule

Jump to solution

I have been asked to write a correlation rule that does the following:

For a given Source IP, trigger whenever Signature ID=278-725002 occurs AND Signature ID=278-716038 has NOT occurred within the last 48 hours.


Signature ID=278-725002                                              #Device completed SSL handshake with server/client

Signature ID=278-716038                                              #WebVPN authentication successful

Is it even possible to correlate on a "within 48 hours"?

Also how would I specify "any" ip?

Thank You!

1 Solution

Accepted Solutions

Re: Date driven correlation rule

Jump to solution

This hasn't triggered yet, but it looks like it should.

9 Replies

Re: Date driven correlation rule

Jump to solution

Hi,

You can correlated based on events occurrences within a specified time window. Just grab"AND" and under it's options you can specify it.

For "any ip" the syntax is "src/dest ip not in 0.0.0.0"

Also if you grab "Funnel" it has option "does not match"

At the moment i don't have access but on Monday i can try to create the rule for you.

Re: Date driven correlation rule

Jump to solution

correlation.pngHere is my attempt.

Re: Date driven correlation rule

Jump to solution

More likely to be something like shown below,

rule.PNG

Re: Date driven correlation rule

Jump to solution

Alexander,

                   Thank You for the reply.

1 question, how do I get the   '!' to preceed the filter? All I was able to do was the (Not In)?

Thanks!

Re: Date driven correlation rule

Jump to solution

Open the second filter box and on the bottom you should see the option

Re: Date driven correlation rule

Jump to solution

So? Does it Wok? if yes please mark the discussion as Answered if not then let us know.

Thanks

Re: Date driven correlation rule

Jump to solution

This hasn't triggered yet, but it looks like it should.

Re: Date driven correlation rule

Jump to solution

Decrease the time window as a test so you could check whether it triggers.

Re: Date driven correlation rule

Jump to solution

Also i believe that you should mark my answer as correct Thank you