2 Replies Latest reply on Sep 29, 2016 5:12 AM by alexander_h

    Correlation not Triggering for ePO malware events

    alexander_h

      Hi Everyone,

       

      Today i was trying to create a correlation rule to notify me about multiple/reoccurring Virus detection on single machine.

      My Datasource is ePO server integrated as regular DS instead of Integrated device.

       

      I've created a correlation as follows:

       

       

       

      I've tried various combinations including normalized rule and ID but no luck.

       

      I've tried with and without grouping however no luck.

       

      P.S: i'm running 9.6 MR5 Combo Device

       

      Thank you in advance,

       

      Alex