When you add a Trellix Application Data Monitor device, database, and correlation rule or component, use Expression Logic or Correlation Logic to build the rule's framework.
Element | Description |
|---|---|
AND | Functions the same as a logical operator in a computer language. Everything that is grouped under this logical element must be true for the condition to be true. Use this option if you want all conditions under this logical element to be met before a rule is triggered. |
OR | Functions the same as a logical operator in a computer language. Only one condition grouped under this element has to be true for this condition to be true. Use this element if you want only one condition to be met before the rule is triggered. |
SET | For correlation rules or components, SET allows you to define conditions and select how many conditions must be true to trigger the rule. |
Each of these elements has a menu with at least two of these options:
Edit — You can edit the default settings.
Remove logical element — You can delete the selected logical element. If it has any children, they aren't deleted and move up in the hierarchy.
Note
This doesn't apply to the root element (the first one in the hierarchy). If you remove the root element, all children are also removed.
Remove logical element and all of its children — You can delete the selected element and all its children from the hierarchy.
When you set up the rule's logic, you must add components to define the conditions for the rule. For correlation rules, you can also add parameters to control the behavior of the rule or component when it executes.