object correlation.create(object/array correlations)
§°§Ó§Ñ? §Þ§Ö§ä§à§Õ §à§Þ§à§Ô§å?§Ñ§Ó§Ñ §ã§ä§Ó§Ñ§â§Ñ?§Ö §ß§à§Ó§Ú§ç §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ñ.
§°§Ó§Ñ? §Þ§Ö§ä§à§Õ ?§Ö §Õ§à§ã§ä§å§á§Ñ§ß §ã§Ñ§Þ§à §ä§Ú§á§å §Ü§à§â§Ú§ã§ß§Ú§Ü§Ñ §ã§å§á§Ö§â §Ñ§Õ§Þ§Ú§ß§Ú§ã§ä§â§Ñ§ä§à§â. §¥§à§Ù§Ó§à§Ý§Ö §Ù§Ñ §á§à§Ù§Ú§Ó§Ñ?§Ö §Þ§Ö§ä§à§Õ§Ö §Þ§à§Ô§å §ã§Ö §à§á§à§Ù§Ó§Ñ§ä§Ú §å §á§à§Õ§Ö§ê§Ñ§Ó§Ñ?§Ú§Þ§Ñ §å§Ý§à§Ô§Ö §Ü§à§â§Ú§ã§ß§Ú§Ü§Ñ. §£§Ú§Õ§Ú§ä§Ö User roles §Ù§Ñ §Ó§Ú§ê§Ö §Ú§ß§æ§à§â§Þ§Ñ§è§Ú?§Ñ.
(object/array)
§¬§à§â§Ö§Ý§Ñ§è§Ú?§Ö §Ù§Ñ §Ü§â§Ö§Ú§â§Ñ?§Ö.
§±§à§â§Ö§Õ §ä§à§Ô§Ñ standard correlation properties, §Þ§Ö§ä§à§Õ §á§â§Ú§ç§Ó§Ñ§ä§Ñ §ã§Ý§Ö§Õ§Ö?§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ö.
Parameter | Type | Description |
---|---|---|
operations | array | Correlation operations §Ù§Ñ §Ü§â§Ö§Ú§â§Ñ?§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ö. |
Parameter behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à |
||
filter | object | Correlation filter §à§Ò?§Ö§Ü§Ñ§ä §Ù§Ñ §Ü§à§â§Ö§Ý§Ñ§è§Ú?§å. Parameter behavior : - §à§Ò§Ñ§Ó§Ö§Ù§ß§à |
(object)
§£§â§Ñ?§Ñ §à§Ò?§Ö§Ü§Ñ§ä §Ü§à?§Ú §ã§Ñ§Õ§â§Ø§Ú ID-§Ú?§Ö§Ó§Ö §Ü§â§Ö§Ú§â§Ñ§ß§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ö §á§à§Õ §ã§Ó§à?§ã§ä§Ó§à§Þ correlationids
. §¯§Ñ§â§Ö§Õ§Ò§Ñ §à §Ó§â§Ñ?§Ö§ß§Ú§Þ ID-§Ú?§Ö§Ó§Ú§Þ§Ñ §à§Õ§Ô§à§Ó§Ñ§â§Ñ §â§Ö§Õ§à§ã§Ý§Ö§Õ§å §á§â§à§ã§Ý§Ö?§Ö§ß§Ú§ç §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ñ.
§¬§â§Ö§Ú§â§Ñ?§ä§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú?§å §Ü§à§â§Ú§ã§ä§Ö?§Ú §Þ§Ö§ä§à§Õ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö AND/OR
§ã§Ñ ?§Ö§Õ§ß§Ú§Þ §å§ã§Ý§à§Ó§à§Þ §Ú ?§Ö§Õ§ß§à§Þ §à§á§Ö§â§Ñ§è§Ú?§à§Þ. §±§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à, §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ñ ?§Ö §Ò§Ú§ä§Ú §à§Þ§à§Ô§å?§Ö§ß§Ñ.
{
"jsonrpc": "2.0",
"method": "correlation.create",
"params": {
"name": "new event tag correlation",
"filter": {
"evaltype": 0,
"conditions": [
{
"type": 1,
"tag": "ok"
}
]
},
"operations": [
{
"type": 0
}
]
},
"id": 1
}
§°§Õ§Ô§à§Ó§à§â:
§¬§â§Ö§Ú§â§Ñ?§ä§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú?§å §Ü§à?§Ñ ?§Ö §Ü§à§â§Ú§ã§ä§Ú§ä§Ú §á§â§Ú§Ý§Ñ§Ô§à?§Ö§ß§Ú §å§ã§Ý§à§Ó §æ§Ú§Ý§ä§Ö§â§Ñ. ID-§Ú?§Ö§Ó§Ú §æ§à§â§Þ§å§Ý§Ö "A" §Ú§Ý§Ú "B" ?§Ö §Ò§Ú§ä§Ú §Ú§Ù§Ñ§Ò§â§Ñ§ß§Ú §á§â§à§Ú§Ù§Ó§à?§ß§à. §´§Ú§á §å§ã§Ý§à§Ó§Ñ ?§Ö §Ò§Ú§ä§Ú "§¤§â§å§á§Ñ §Õ§à§Þ§Ñ?§Ú§ß§Ñ" §ã§Ñ §à§á§Ö§â§Ñ§ä§à§â§à§Þ "<>".
{
"jsonrpc": "2.0",
"method": "correlation.create",
"params": {
"name": "new host group correlation",
"description": "a custom description",
"status": 0,
"filter": {
"evaltype": 3,
"formula": "A or B",
"conditions": [
{
"type": 2,
"operator": 1,
"formulaid": "A"
},
{
"type": 2,
"operator": 1,
"formulaid": "B"
}
]
},
"operations": [
{
"type": 1
}
]
},
"id": 1
}
§°§Õ§Ô§à§Ó§à§â:
CCorrelation::create() §å ui/include/classes/api/services/CCorrelation.php.