Open
Description
I'm coming from a Graylog background where the correlation engine supports the following methods:
- Rule A triggers at least X times
- (optional) AND Rule B doesn't trigger AND followed by Rule C
- (optional) AND Rule D doesn't trigger in the next Y timespan
- (optional) AND Rule E triggers at least Z times
- etc.
Using the latest V2 specs the optional scenarios are not possible (at least from my understanding) without creating separate Sigma sub-rules, especially when the counting should differ from rule to rule.
Is it intention that such correlations are not possible in one single rule, probably for compatibility for other SIEM systems?
Metadata
Metadata
Assignees
Labels
No labels