If you set a correlation rule to group by a specific field, you can override a component in the rule to match on a different field.
For example, if you set the Group by field in a correlation rule to source IP address, you can override a component of the rule to use the destination IP address. This means that all events have the same source IP address except the events that match the overridden component. Those events have the same destination IP address as the source IP address of the other events. Override rule components to look for a single event going from a particular destination followed by another event that originates from that destination.
On the Trellix ESM console, click the Policy Editor icon
.Click Correlation in the Rule Types pane, select a rule, then click → .
Drag and drop the Match Component logic element
in the Correlation logic area, then click the menu icon
, or click the menu icon of an existing Match Component element in the Correlation logic area.Select Edit, click Advanced Options, then select Override Group By and click Configure.
On the Configure Group By overrides page, select the override field, then click OK.