object correlation.update(§à§Ò§ì§Ö§Ü§ä/§Þ§Ñ§ã§ã§Ú§Ó correlations)
§¿§ä§à§ä §Þ§Ö§ä§à§Õ §á§à§Ù§Ó§à§Ý§ñ§Ö§ä §ã§à§Ù§Õ§Ñ§Ó§Ñ§ä§î §ß§à§Ó§í§Ö §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú.
§¿§ä§à§ä §Þ§Ö§ä§à§Õ §Õ§à§ã§ä§å§á§Ö§ß §ä§à§Ý§î§Ü§à §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ð §ã §ä§Ú§á§à§Þ §Õ§à§ã§ä§å§á§Ñ §³§å§á§Ö§â-§Ñ§Õ§Þ§Ú§ß§Ú§ã§ä§â§Ñ§ä§à§â. §²§Ñ§Ù§â§Ö§ê§Ö§ß§Ú§ñ §ß§Ñ §Ó§í§Ù§à§Ó §Þ§Ö§ä§à§Õ§Ñ §Þ§à§Ø§ß§à §à§ä§à§Ù§Ó§Ñ§ä§î §Ó §ß§Ñ§ã§ä§â§à§Û§Ü§Ñ§ç §â§à§Ý§Ö§Û §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ. §¥§à§á§à§Ý§ß§Ú§ä§Ö§Ý§î§ß§å§ð §Ú§ß§æ§à§â§Þ§Ñ§è§Ú§ð §ã§Þ. §Ó §â§Ñ§Ù§Õ§Ö§Ý§Ö §²§à§Ý§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û.
(object/array)
§³§à§Ù§Õ§Ñ§Ó§Ñ§Ö§Þ§í§Ö §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú.
§£ §Õ§à§á§à§Ý§ß§Ö§ß§Ú§Ö §Ü §ã§ä§Ñ§ß§Õ§Ñ§â§ä§ß§í§Þ §ã§Ó§à§Û§ã§ä§Ó§Ñ§Þ §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú, §ï§ä§à§ä §Þ§Ö§ä§à§Õ §á§â§Ú§ß§Ú§Þ§Ñ§Ö§ä §ã§Ý§Ö§Õ§å§ð§ë§Ú§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í.
§±§Ñ§â§Ñ§Þ§Ö§ä§â | §´§Ú§á | §°§á§Ú§ã§Ñ§ß§Ú§Ö |
---|---|---|
operations (§à§Ò§ñ§Ù§Ñ§ä§Ö§Ý§î§ß§í§Û) |
array | §¬§à§â§â§Ö§Ý§ñ§è§Ú§ñ §à§á§Ö§â§Ñ§è§Ú§Û §Õ§Ý§ñ §ã§à§Ù§Õ§Ñ§ß§Ú§ñ §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú. |
filter (§à§Ò§ñ§Ù§Ñ§ä§Ö§Ý§î§ß§í§Û) |
object | §°§Ò§ì§Ö§Ü§ä §æ§Ú§Ý§î§ä§â§Ñ §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú §Õ§Ý§ñ §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú. |
(object)
§£§à§Ù§Ó§â§Ñ§ë§Ñ§Ö§ä §à§Ò§ì§Ö§Ü§ä, §Ü§à§ä§à§â§í§Û §ã§à§Õ§Ö§â§Ø§Ú§ä ID §ã§à§Ù§Õ§Ñ§ß§ß§í§ç §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Û §á§à§Õ §ã§Ó§à§Û§ã§ä§Ó§à§Þ correlationids
. §±§à§â§ñ§Õ§à§Ü §Ó§à§Ù§Ó§â§Ñ§ë§Ñ§Ö§Þ§í§ç ID §ã§à§Ó§á§Ñ§Õ§Ñ§Ö§ä §ã §á§à§â§ñ§Õ§Ü§à§Þ §á§Ö§â§Ö§Õ§Ñ§ß§ß§í§ç §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Û.
§³§à§Ù§Õ§Ñ§ß§Ú§Ö §Ü§à§â§â§Ö§Ý§ñ§è§Ú§Ú, §Ü§à§ä§à§â§à§Ö §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä §Þ§Ö§ä§à§Õ §Ó§í§é§Ú§ã§Ý§Ö§ß§Ú§ñ §ª/§ª§§ª
(AND/OR), §ã §à§Õ§ß§Ú§Þ §å§ã§Ý§à§Ó§Ú§Ö§Þ §Ú §à§Õ§ß§à§Û §à§á§Ö§â§Ñ§è§Ú§Ö§Û. §±§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð §Ü§à§â§â§Ö§Ý§ñ§è§Ú§ñ §Ò§å§Õ§Ö§ä §Ñ§Ü§ä§Ú§Ó§Ú§â§à§Ó§Ñ§ß§Ñ.
§©§Ñ§á§â§à§ã:
{
"jsonrpc": "2.0",
"method": "correlation.create",
"params": {
"name": "new event tag correlation",
"filter": {
"evaltype": 0,
"conditions": [
{
"type": 1,
"tag": "ok"
}
]
},
"operations": [
{
"type": 0
}
]
},
"auth": "343baad4f88b4106b9b5961e77437688",
"id": 1
}
§°§ä§Ó§Ö§ä:
§³§à§Ù§Õ§Ñ§Û§ä§Ö §Ü§à§â§â§Ö§Ý§ñ§è§Ú§ð, §Ü§à§ä§à§â§Ñ§ñ §Ò§å§Õ§Ö§ä §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î§ã§Ü§à§Ö §å§ã§Ý§à§Ó§Ú§Ö §æ§Ú§Ý§î§ä§â§Ñ. §ª§Õ§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§ä§à§â§í §æ§à§â§Þ§å§Ý§í ?A? §Ú§Ý§Ú ?B? §Ó§í§Ò§â§Ñ§ß§í §á§â§à§Ú§Ù§Ó§à§Ý§î§ß§à. §´§Ú§á §å§ã§Ý§à§Ó§Ú§ñ §Ò§å§Õ§Ö§ä "Host group" §ã §à§á§Ö§â§Ñ§ä§à§â§à§Þ "<>".
§©§Ñ§á§â§à§ã:
{
"jsonrpc": "2.0",
"method": "correlation.create",
"params": {
"name": "new host group correlation",
"description": "a custom description",
"status": 0,
"filter": {
"evaltype": 3,
"formula": "A or B",
"conditions": [
{
"type": 2,
"operator": 1,
"formulaid": "A"
},
{
"type": 2,
"operator": 1,
"formulaid": "B"
}
]
},
"operations": [
{
"type": 1
}
]
},
"auth": "343baad4f88b4106b9b5961e77437688",
"id": 1
}
§°§ä§Ó§Ö§ä:
CCorrelation::create() §Ó ui/include/classes/api/services/CCorrelation.php.