Defining event policies for enrichment, correlation, notification, and suppression
Each event policy consists of the following details:
- The basic policy information such as the name, description, and precedence.
- An event selection criteria, which is the first filter based on which incoming events are selected for further processing.
- A time frame for the policy to be active.
- A built-in evaluation order for the different types of event policies configured.
- The configuration settings that define actions to determine how the events must be processed.
Except the evaluation order, you can configure these details while configuring an event policy.
Event enrichment and correlation
-
Advanced, time-based, and dynamic enrichment policiesCreating and enabling event policiesEvent correlation for aggregating related eventsTip: For faster searching, add an asterisk to the end of your partial query. Example: cert*