2 Replies Latest reply on Sep 29, 2016 5:12 AM by alexander_h

    Correlation not Triggering for ePO malware events


      Hi Everyone,


      Today i was trying to create a correlation rule to notify me about multiple/reoccurring Virus detection on single machine.

      My Datasource is ePO server integrated as regular DS instead of Integrated device.


      I've created a correlation as follows:




      I've tried various combinations including normalized rule and ID but no luck.


      I've tried with and without grouping however no luck.


      P.S: i'm running 9.6 MR5 Combo Device


      Thank you in advance,