§à§Ò§ì§Ö§Ü§ä correlation.create(§à§Ò§ì§Ö§Ü§ä/§Þ§Ñ§ã§ã§Ú§Ó §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú)
§¿§ä§à§ä §Þ§Ö§ä§à§Õ §á§à§Ù§Ó§à§Ý§ñ§Ö§ä §ã§à§Ù§Õ§Ñ§Ó§Ñ§ä§î §ß§à§Ó§í§Ö §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú.
(§à§Ò§ì§Ö§Ü§ä/§Þ§Ñ§ã§ã§Ú§Ó)
§³§à§Ù§Õ§Ñ§Ó§Ñ§Ö§Þ§í§Ö §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú.
§£ §Õ§à§á§à§Ý§ß§Ö§ß§Ú§Ö §Ü §ã§ä§Ñ§ß§Õ§Ñ§â§ä§ß§í§Þ §ã§Ó§à§Û§ã§ä§Ó§Ñ§Þ §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú, §ï§ä§à§ä §Þ§Ö§ä§à§Õ §á§â§Ú§ß§Ú§Þ§Ñ§Ö§ä §ã§Ý§Ö§Õ§å§ð§ë§Ú§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í.
§±§Ñ§â§Ñ§Þ§Ö§ä§â | §´§Ú§á | §°§á§Ú§ã§Ñ§ß§Ú§Ö |
---|---|---|
operations (§ä§â§Ö§Ò§å§Ö§ä§ã§ñ) |
§Þ§Ñ§ã§ã§Ú§Ó | §³§à§Ù§Õ§Ñ§Ó§Ñ§Ö§Þ§í§Ö §à§á§Ö§â§Ñ§è§Ú§Ú §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú §Õ§Ý§ñ §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú. |
filter (§ä§â§Ö§Ò§å§Ö§ä§ã§ñ) |
§à§Ò§ì§Ö§Ü§ä | §°§Ò§ì§Ö§Ü§ä §æ§Ú§Ý§î§ä§â§Ñ §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú §Õ§Ý§ñ §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú. |
(§à§Ò§ì§Ö§Ü§ä)
§£§à§Ù§Ó§â§Ñ§ë§Ñ§Ö§ä §à§Ò§ì§Ö§Ü§ä, §Ü§à§ä§à§â§í§Û §ã§à§Õ§Ö§â§Ø§Ú§ä ID §ã§à§Ù§Õ§Ñ§ß§ß§í§ç §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Û §á§à§Õ §ã§Ó§à§Û§ã§ä§Ó§à§Þ correlationids
. §±§à§â§ñ§Õ§à§Ü §Ó§à§Ù§Ó§â§Ñ§ë§Ñ§Ö§Þ§í§ç ID §ã§à§Ó§á§Ñ§Õ§Ñ§Ö§ä §ã §á§à§â§ñ§Õ§Ü§à§Þ §á§Ö§â§Ö§Õ§Ñ§ß§ß§í§ç §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Û.
§³§à§Ù§Õ§Ñ§ß§Ú§Ö §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú, §Ü§à§ä§à§â§à§Ö §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä §Þ§Ö§ä§à§Õ §Ó§í§é§Ú§ã§Ý§Ö§ß§Ú§ñ §ª/§ª§§ª
, §ã §à§Õ§ß§Ú§Þ §å§ã§Ý§à§Ó§Ú§Ö§Þ §Ú §à§Õ§ß§à§Û §à§á§Ö§â§Ñ§è§Ú§Ö§Û. §±§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð §Ü§à§â§â§Ö§Ý§ñ§è§Ú§ñ §Ò§å§Õ§Ö§ä §Ñ§Ü§ä§Ú§Ó§Ú§â§à§Ó§Ñ§ß§Ñ.
§©§Ñ§á§â§à§ã:
{
"jsonrpc": "2.0",
"method": "correlation.create",
"params": {
"name": "new event tag correlation",
"filter": {
"evaltype": 0,
"conditions": [
{
"type": 1,
"tag": "ok"
}
]
},
"operations": [
{
"type": 0
}
]
},
"auth": "343baad4f88b4106b9b5961e77437688",
"id": 1
}
§°§ä§Ó§Ö§ä:
§³§à§Ù§Õ§Ñ§ß§Ú§Ö §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú, §Ü§à§ä§à§â§Ñ§ñ §Ò§å§Õ§Ö§ä §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î§ã§Ü§à§Ö §å§ã§Ý§à§Ó§Ú§Ö §æ§Ú§Ý§î§ä§â§Ñ§è§Ú§Ú. ID "A" §Ú "B" §Ó §æ§à§â§Þ§å§Ý§Ö §Ò§í§Ý§Ú §Ó§í§Ò§â§Ñ§ß§í §ã§Ý§å§é§Ñ§Û§ß§à. §´§Ú§á §å§ã§Ý§à§Ó§Ú§ñ §Ò§å§Õ§Ö§ä "§¤§â§å§á§á§Ñ §å§Ù§Ý§à§Ó §ã§Ö§ä§Ú" §ã §à§á§Ö§â§Ñ§ä§à§â§à§Þ "<>".
§©§Ñ§á§â§à§ã:
{
"jsonrpc": "2.0",
"method": "correlation.create",
"params": {
"name": "new host group correlation",
"description": "a custom description",
"status": 0,
"filter": {
"evaltype": 3,
"formula": "A or B",
"conditions": [
{
"type": 2,
"operator": 1,
"formulaid": "A"
},
{
"type": 2,
"operator": 1,
"formulaid": "B"
}
]
},
"operations": [
{
"type": 1
}
]
},
"auth": "343baad4f88b4106b9b5961e77437688",
"id": 1
}
§°§ä§Ó§Ö§ä:
CCorrelation::create() §Ó frontends/php/include/classes/api/services/CCorrelation.php.