Rule Management

Using the Management > Advanced Features > Rule Management menu, an admin user can add, edit, or delete triggers and aggregation rules.

  • Triggers: can be created after defining a correlation Blok. Triggers describe what action should be taken once a correlation Blok is triggered.
  • Aggregation rules: can optimize the performance of aggregation search queries.