The following correlation rule came as part of an email content pack and I want to change it slightly but want to make sure I understand what it is doing as testing the deviation correlation rules is harder than event based ones.
The correlation rule in question is "Email - Abnormal Volumes of Outbound Email" and looks as below. The "filter" gate has a threshold number of events of 1000 in one hour.
What I am wondering is the following:
Cheers for any help on this.