Correlation rules interpret pattern results in the data. Correlation analyzes data and detects patterns in the data flow, generates alerts for these patterns, and inserts alerts into the Trellix Enterprise Security Manager - Event Receiver alert database.
Correlation rules are separate and distinct from firewalls or standard rules with attributes that specify its behavior. Each Trellix Enterprise Security Manager - Event Receiver gets a set of correlation rules from a Trellix ESM (deployed correlation rule set), which is composed of zero or more correlation rules set with user-defined parameter values. Trellix ESM includes a base set of correlation rules, which the rule update server updates.
Note
The rules on the rule update server include default values. When you update the base correlation engine rule set, customize these default values so they properly represent your network. If you deploy these rules without changing the default values, they can generate false positives or false negatives.
When you configure a data source, you enable correlation. Only one correlation data source can be configured per Trellix Enterprise Security Manager - Event Receiver, in a fashion similar to configuring syslog or OPSEC. Once you configure the correlation data source, you can edit the base correlation rule set to create the deployed correlation rule set using the Correlation Rule Editor. You can enable or disable each correlation rule and set the value of each rule's user definable parameters. You can also create custom rules and add correlation components to correlation rules.