Áú»¢¶Ä²©

correlation.create

§°§á§Ú§ã

object correlation.create(object/array correlations)

§°§Ó§Ñ? §Þ§Ö§ä§à§Õ §à§Þ§à§Ô§å?§Ñ§Ó§Ñ §ã§ä§Ó§Ñ§â§Ñ?§Ö §ß§à§Ó§Ú§ç §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ñ.

§°§Ó§Ñ? §Þ§Ö§ä§à§Õ ?§Ö §Õ§à§ã§ä§å§á§Ñ§ß §ã§Ñ§Þ§à §ä§Ú§á§å §Ü§à§â§Ú§ã§ß§Ú§Ü§Ñ §ã§å§á§Ö§â §Ñ§Õ§Þ§Ú§ß§Ú§ã§ä§â§Ñ§ä§à§â. §¥§à§Ù§Ó§à§Ý§Ö §Ù§Ñ §á§à§Ù§Ú§Ó§Ñ?§Ö §Þ§Ö§ä§à§Õ§Ö §Þ§à§Ô§å §ã§Ö §à§á§à§Ù§Ó§Ñ§ä§Ú §å §á§à§Õ§Ö§ê§Ñ§Ó§Ñ?§Ú§Þ§Ñ §å§Ý§à§Ô§Ö §Ü§à§â§Ú§ã§ß§Ú§Ü§Ñ. §£§Ú§Õ§Ú§ä§Ö User roles §Ù§Ñ §Ó§Ú§ê§Ö §Ú§ß§æ§à§â§Þ§Ñ§è§Ú?§Ñ.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú

(object/array) §¬§à§â§Ö§Ý§Ñ§è§Ú?§Ö §Ù§Ñ §Ü§â§Ö§Ú§â§Ñ?§Ö.

§±§à§â§Ö§Õ §ä§à§Ô§Ñ standard correlation properties, §Þ§Ö§ä§à§Õ §á§â§Ú§ç§Ó§Ñ§ä§Ñ §ã§Ý§Ö§Õ§Ö?§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ö.

Parameter Type Description
operations array Correlation operations §Ù§Ñ §Ü§â§Ö§Ú§â§Ñ?§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ö.


Parameter behavior:
- §à§Ò§Ñ§Ó§Ö§Ù§ß§à
filter object Correlation filter §à§Ò?§Ö§Ü§Ñ§ä §Ù§Ñ §Ü§à§â§Ö§Ý§Ñ§è§Ú?§å.

Parameter behavior :
- §à§Ò§Ñ§Ó§Ö§Ù§ß§à

§±§à§Ó§â§Ñ§ä§ß§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú

(object) §£§â§Ñ?§Ñ §à§Ò?§Ö§Ü§Ñ§ä §Ü§à?§Ú §ã§Ñ§Õ§â§Ø§Ú ID-§Ú?§Ö§Ó§Ö §Ü§â§Ö§Ú§â§Ñ§ß§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ö §á§à§Õ §ã§Ó§à?§ã§ä§Ó§à§Þ correlationids. §¯§Ñ§â§Ö§Õ§Ò§Ñ §à §Ó§â§Ñ?§Ö§ß§Ú§Þ ID-§Ú?§Ö§Ó§Ú§Þ§Ñ §à§Õ§Ô§à§Ó§Ñ§â§Ñ §â§Ö§Õ§à§ã§Ý§Ö§Õ§å §á§â§à§ã§Ý§Ö?§Ö§ß§Ú§ç §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ñ.

§±§â§Ú§Þ§Ö§â§Ú

§¬§â§Ö§Ú§â§Ñ?§Ö §ß§à§Ó§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ö §à§Ù§ß§Ñ§Ü§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ

§¬§â§Ö§Ú§â§Ñ?§ä§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú?§å §Ü§à§â§Ú§ã§ä§Ö?§Ú §Þ§Ö§ä§à§Õ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö AND/OR §ã§Ñ ?§Ö§Õ§ß§Ú§Þ §å§ã§Ý§à§Ó§à§Þ §Ú ?§Ö§Õ§ß§à§Þ §à§á§Ö§â§Ñ§è§Ú?§à§Þ. §±§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à, §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ñ ?§Ö §Ò§Ú§ä§Ú §à§Þ§à§Ô§å?§Ö§ß§Ñ.

Request:

{
       "jsonrpc": "2.0",
       "method": "correlation.create",
       "params": {
       "name": "new event tag correlation",
       "filter": {
       "evaltype": 0,
       "conditions": [
       {
       "type": 1,
       "tag": "ok"
       }
       ]
       },
       "operations": [
       {
       "type": 0
       }
       ]
       },
       "id": 1
       }

§°§Õ§Ô§à§Ó§à§â:

{
       "jsonrpc": "2.0",
       "result": {
       "correlationids": [
       "1"
       ]
       },
       "id": 1
       }

§¬§à§â§Ú§ê?§Ö?§Ö §æ§Ú§Ý§ä§Ö§â§Ñ §á§â§Ú§Ý§Ñ§Ô§à?§Ö§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ

§¬§â§Ö§Ú§â§Ñ?§ä§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú?§å §Ü§à?§Ñ ?§Ö §Ü§à§â§Ú§ã§ä§Ú§ä§Ú §á§â§Ú§Ý§Ñ§Ô§à?§Ö§ß§Ú §å§ã§Ý§à§Ó §æ§Ú§Ý§ä§Ö§â§Ñ. ID-§Ú?§Ö§Ó§Ú §æ§à§â§Þ§å§Ý§Ö "A" §Ú§Ý§Ú "B" ?§Ö §Ò§Ú§ä§Ú §Ú§Ù§Ñ§Ò§â§Ñ§ß§Ú §á§â§à§Ú§Ù§Ó§à?§ß§à. §´§Ú§á §å§ã§Ý§à§Ó§Ñ ?§Ö §Ò§Ú§ä§Ú "§¤§â§å§á§Ñ §Õ§à§Þ§Ñ?§Ú§ß§Ñ" §ã§Ñ §à§á§Ö§â§Ñ§ä§à§â§à§Þ "<>".

Request:

{
       "jsonrpc": "2.0",
       "method": "correlation.create",
       "params": {
       "name": "new host group correlation",
       "description": "a custom description",
       "status": 0,
       "filter": {
       "evaltype": 3,
       "formula": "A or B",
       "conditions": [
       {
       "type": 2,
       "operator": 1,
       "formulaid": "A"
       },
       {
       "type": 2,
       "operator": 1,
       "formulaid": "B"
       }
       ]
       },
       "operations": [
       {
       "type": 1
       }
       ]
       },
       "id": 1
       }

§°§Õ§Ô§à§Ó§à§â:

{
       "jsonrpc": "2.0",
       "result": {
       "correlationids": [
       "2"
       ]
       },
       "id": 1
       }

§±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §ä§Ñ§Ü§à?§Ö

§ª§Ù§Ó§à§â

CCorrelation::create() §å ui/include/classes/api/services/CCorrelation.php.