§³§Ý§Ö§Õ§Ö?§Ú §à§Ò?§Ö§Ü§ä§Ú §ã§å §Õ§Ú§â§Ö§Ü§ä§ß§à §á§à§Ó§Ö§Ù§Ñ§ß§Ú §ã§Ñ correlation
´¡±Ê±õ-?§Ö§Þ.
§°§Ò?§Ö§Ü§Ñ§ä §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ö §Ú§Þ§Ñ §ã§Ý§Ö§Õ§Ö?§Ñ §ã§Ó§à?§ã§ä§Ó§Ñ.
Property | Type | Description |
---|---|---|
correlationid | ID | ID §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ö. Property behavior: - §ã§Ñ§Þ§à §Ù§Ñ §é§Ú§ä§Ñ?§Ö - §à§Ò§Ñ§Ó§Ö§Ù§ß§à §Ù§Ñ §à§á§Ö§â§Ñ§è§Ú?§Ö §Ñ§Ø§å§â§Ú§â§Ñ?§Ñ |
name | string | §¯§Ñ§Ù§Ú§Ó §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ö. Property behavior: - §á§à§ä§â§Ö§Ò§ß§à §Ù§Ñ §à§á§Ö§â§Ñ§è§Ú?§Ö §Ü§â§Ö§Ú§â§Ñ?§Ñ |
name | string | §°§á§Ú§ã §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ö. |
status | integer | §¥§Ñ §Ý§Ú ?§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ñ §à§Þ§à§Ô§å?§Ö§ß§Ñ §Ú§Ý§Ú §à§ß§Ö§Þ§à§Ô§å?§Ö§ß§Ñ. §®§à§Ô§å?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: 0 - (§á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à) §à§Þ§à§Ô§å?§Ö§ß§à; 1 - §à§ß§Ö§Þ§à§Ô§å?§Ö§ß§à. |
§°§Ò?§Ö§Ü§Ñ§ä §à§á§Ö§â§Ñ§è§Ú?§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ö §Õ§Ö§æ§Ú§ß§Ú§ê§Ö §à§á§Ö§â§Ñ§è§Ú?§å §Ü§à?§Ñ ?§Ö §ã§Ö §Ú§Ù§Ó§â§ê§Ú§ä§Ú §Ü§Ñ§Õ§Ñ §ã§Ö §Ú§Ù§Ó§â§ê§Ú §Ü§à§â§Ö§Ý§Ñ§è§Ú?§Ñ. §ª§Þ§Ñ §ã§Ý§Ö§Õ§Ö?§Ñ §ã§Ó§à?§ã§ä§Ó§Ñ.
Property | Type | Description |
---|---|---|
type | integer | §´§Ú§á §à§á§Ö§â§Ñ§è§Ú?§Ö. §®§à§Ô§å?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: 0 - §Ù§Ñ§ä§Ó§à§â§Ú §ã§ä§Ñ§â§Ö §Õ§à§Ô§Ñ?§Ñ?§Ö; 1 - §Ù§Ñ§ä§Ó§à§â§Ú §ß§à§Ó§Ú §Õ§à§Ô§Ñ?§Ñ?. Property behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à |
§°§Ò?§Ö§Ü§Ñ§ä §Ü§à§â§Ö§Ý§Ñ§è§Ú§à§ß§à§Ô §æ§Ú§Ý§ä§Ö§â§Ñ §Õ§Ö§æ§Ú§ß§Ú§ê§Ö §ã§Ü§å§á §å§ã§Ý§à§Ó§Ñ §Ü§à?§Ú §Þ§à§â§Ñ?§å §Ò§Ú§ä§Ú §Ú§ã§á§å?§Ö§ß§Ú §Õ§Ñ §Ò§Ú §ã§Ö §Ú§Ù§Ó§â§ê§Ú§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ú§ã§Ñ§ß§Ö §Ü§à§â§Ö§Ý§Ñ§è§Ú§à§ß§Ö §à§á§Ö§â§Ñ§è§Ú?§Ö. §ª§Þ§Ñ §ã§Ý§Ö§Õ§Ö?§Ñ §ã§Ó§à?§ã§ä§Ó§Ñ.
Property | Type | Description |
---|---|---|
conditions | array | §³§Ü§å§á filter conditions §Ü§à?§Ú §ã§Ö §Ü§à§â§Ú§ã§ä§Ú §Ù§Ñ §æ§Ú§Ý§ä§â§Ú§â§Ñ?§Ö §â§Ö§Ù§å§Ý§ä§Ñ§ä§Ñ. §µ§ã§Ý§à§Ó§Ú ?§Ö §Ò§Ú§ä§Ú §ã§à§â§ä§Ú§â§Ñ§ß§Ú §á§à §â§Ö§Õ§à§ã§Ý§Ö§Õ§å ?§Ú§ç§à§Ó§à§Ô §á§à§ã§ä§Ñ§Ó?§Ñ?§Ñ §å §æ§à§â§Þ§å§Ý§å. Property behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à |
evaltype | integer | §®§Ö§ä§à§Õ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö §æ§Ú§Ý§ä§Ö§â§Ñ §å§ã§Ý§à§Ó§Ñ. §®§à§Ô§å?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: 0 - §Ú/§Ú§Ý§Ú; 1 - §Ú; 2 - §Ú§Ý§Ú; 3 - §á§â§Ú§Ý§Ñ§Ô§à?§Ö§ß§Ú §Ú§Ù§â§Ñ§Ù. Property behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à |
eval_formula | string | §¤§Ö§ß§Ö§â§Ú§ã§Ñ§ß§Ú §Ú§Ù§â§Ñ§Ù §Ü§à?§Ú ?§Ö §ã§Ö §Ü§à§â§Ú§ã§ä§Ú§ä§Ú §Ù§Ñ §á§â§à§è§Ö§ß§å §å§ã§Ý§à§Ó§Ñ §æ§Ú§Ý§ä§Ö§â§Ñ. §ª§Ù§â§Ñ§Ù §ã§Ñ§Õ§â§Ø§Ú ID-§Ú?§Ö§Ó§Ö §Ü§à?§Ú §â§Ö§æ§Ö§â§Ú§ê§å §ß§Ñ §ã§á§Ö§è§Ú§æ§Ú§é§ß§Ö §å§ã§Ý§à§Ó§Ö §æ§Ú§Ý§ä§Ö§â§Ñ §á§â§Ö§Ü§à formulaid §à§ã§à§Ò§Ú§ß§Ö. §£§â§Ö§Õ§ß§à§ã§ä eval_formula ?§Ö ?§Ö§Õ§ß§Ñ§Ü§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú formula §Ù§Ñ §æ§Ú§Ý§ä§Ö§â§Ö §ã§Ñ §á§â§Ú§Ý§Ñ§Ô§à?§Ö§ß§Ú§Þ §Ú§Ù§â§Ñ§Ù§à§Þ.Property behavior: - * §ã§Ñ§Þ§à §Ù§Ñ §é§Ú§ä§Ñ?§Ö* |
formula | string | §¬§à§â§Ú§ã§ß§Ú§é§Ü§Ú §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß §Ú§Ù§â§Ñ§Ù §Ü§à?§Ú §ã§Ö §Ü§à§â§Ú§ã§ä§Ú§ä§Ú §Ù§Ñ §á§â§à§è§Ö§ß§å §å§ã§Ý§à§Ó§Ñ §æ§Ú§Ý§ä§Ö§â§Ñ §ã§Ñ §á§â§Ú§Ý§Ñ§Ô§à?§Ö§ß§Ú§Þ §Ú§Ù§â§Ñ§Ù§à§Þ. §ª§Ù§â§Ñ§Ù §Þ§à§â§Ñ §ã§Ñ§Õ§â§Ø§Ñ§ä§Ú ID-§Ú?§Ö§Ó§Ö §Ü§à?§Ú §â§Ö§æ§Ö§â§Ú§ê§å §ß§Ñ §ã§á§Ö§è§Ú§æ§Ú§é§ß§Ö §å§ã§Ý§à§Ó§Ö §æ§Ú§Ý§ä§Ö§â§Ñ §á§â§Ö§Ü§à formulaid . ID-§Ú?§Ö§Ó§Ú §Ü§à?§Ú §ã§Ö §Ü§à§â§Ú§ã§ä§Ö §å §Ú§Ù§â§Ñ§Ù§å §Þ§à§â§Ñ?§å §ä§Ñ§é§ß§à §Õ§Ñ §à§Õ§Ô§à§Ó§Ñ§â§Ñ?§å §à§ß§Ú§Þ§Ñ §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§Ú§Þ §å §å§ã§Ý§à§Ó§Ú§Þ§Ñ §æ§Ú§Ý§ä§Ö§â§Ñ: §ß§Ú?§Ö§Õ§Ñ§ß §å§ã§Ý§à§Ó §ß§Ö §Þ§à§Ø§Ö §à§ã§ä§Ñ§ä§Ú §ß§Ö§Ú§ã§Ü§à§â§Ú§ê?§Ö§ß §Ú§Ý§Ú §Ú§Ù§à§ã§ä§Ñ§Ó?§Ö§ß.Property behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à §Ñ§Ü§à ?§Ö evaltype §á§à§Õ§Ö§ê§Ö§ß §ß§Ñ "§á§â§Ú§Ý§Ñ§Ô§à?§Ö§ß§Ú §Ú§Ù§â§Ñ§Ù" |
§°§Ò?§Ö§Ü§Ñ§ä §å§ã§Ý§à§Ó§Ñ §Ü§à§â§Ö§Ý§Ñ§è§Ú§à§ß§à§Ô §æ§Ú§Ý§ä§Ö§â§Ñ §Õ§Ö§æ§Ú§ß§Ú§ê§Ö §à§Õ§â§Ö?§Ö§ß§Ú §å§ã§Ý§à§Ó §Ü§à?§Ú §Þ§à§â§Ñ §Ò§Ú§ä§Ú §á§â§à§Ó§Ö§â§Ö§ß §á§â§Ö §á§à§Ü§â§Ö§ä§Ñ?§Ñ §Ü§à§â§Ö§Ý§Ñ§è§Ú§à§ß§Ú§ç §à§á§Ö§â§Ñ§è§Ú?§Ñ.
Property | Type | Description |
---|---|---|
type | integer | §´§Ú§á §å§ã§Ý§à§Ó§Ñ. §®§à§Ô§å?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: 0 ¨C §ã§ä§Ñ§â§Ñ §à§Ù§ß§Ñ§Ü§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ; 1 ¨C §ß§à§Ó§Ñ §à§Ù§ß§Ñ§Ü§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ; 2 ¨C §ß§à§Ó§Ñ §Ô§â§å§á§Ñ §Õ§à§Þ§Ñ?§Ú§ß§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ; 3 - §á§Ñ§â §à§Ù§ß§Ñ§Ü§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ; 4 - §ã§ä§Ñ§â§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä §à§Ù§ß§Ñ§Ü§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ; 5 - §ß§à§Ó§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä §à§Ù§ß§Ñ§Ü§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ. Property behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à |
tag | string | §°§Ù§ß§Ñ§Ü§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ (§ã§ä§Ñ§â§Ñ §Ú§Ý§Ú §ß§à§Ó§Ñ). Property behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à §Ñ§Ü§à ?§Ö type §á§à§Õ§Ö§ê§Ö§ß §ß§Ñ "§ã§ä§Ñ§â§Ñ §à§Ù§ß§Ñ§Ü§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ", "§ß§à§Ó§Ñ §à§Ù§ß§Ñ§Ü§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ", "§Ó§â§Ö§Õ§ß§à§ã§ä §ã§ä§Ñ§â§Ö §à§Ù§ß§Ñ§Ü§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ" §Ú§Ý§Ú "§Ó§â§Ö§Õ§ß§à§ã§ä §ß§à§Ó§Ö §à§Ù§ß§Ñ§Ü§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ" |
groupid | ID | ID §Ô§â§å§á§Ö §Õ§à§Þ§Ñ?§Ú§ß§Ñ. Property behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à §Ñ§Ü§à ?§Ö type §á§à§Õ§Ö§ê§Ö§ß §ß§Ñ "§ß§à§Ó§Ñ §Ô§â§å§á§Ñ §Õ§à§Þ§Ñ?§Ú§ß§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ" |
oldtag | string | §³§ä§Ñ§â§Ñ §à§Ù§ß§Ñ§Ü§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ. Property behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à §Ñ§Ü§à ?§Ö type §á§à§Õ§Ö§ê§Ö§ß §ß§Ñ "§á§Ñ§â §à§Ù§ß§Ñ§Ü§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ " |
newtag | string | §³§ä§Ñ§â§Ñ §à§Ù§ß§Ñ§Ü§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ. Property behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à §Ñ§Ü§à ?§Ö type §á§à§Õ§Ö§ê§Ö§ß §ß§Ñ "§á§Ñ§â §à§Ù§ß§Ñ§Ü§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ " |
value | string | §£§â§Ö§Õ§ß§à§ã§ä §à§Ù§ß§Ñ§Ü§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ (§ã§ä§Ñ§â§Ñ §Ú§Ý§Ú §ß§à§Ó§Ñ). Property behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à §Ñ§Ü§à ?§Ö §á§à§Õ§Ö§ê§Ö§ß type §ß§Ñ "§Ó§â§Ö§Õ§ß§à§ã§ä §ã§ä§Ñ§â§Ö §à§Ù§ß§Ñ§Ü§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ" §Ú§Ý§Ú "§Ó§â§Ö§Õ§ß§à§ã§ä §ß§à§Ó§Ö §à§Ù§ß§Ñ§Ü§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ" |
formulaid | string | §±§â§à§Ú§Ù§Ó§à?§ß§Ú ?§Ö§Õ§Ú§ß§ã§ä§Ó§Ö§ß§Ú ID §Ü§à?§Ú §ã§Ö §Ü§à§â§Ú§ã§ä§Ú §Ù§Ñ §â§Ö§æ§Ö§â§Ö§ß§è§Ú§â§Ñ?§Ö §å§ã§Ý§à§Ó§Ñ §å §á§â§Ú§Ý§Ñ§Ô§à?§Ö§ß§à§Þ §Ú§Ù§â§Ñ§Ù§å. §®§à§Ø§Ö §Õ§Ñ §ã§Ñ§Õ§â§Ø§Ú §ã§Ñ§Þ§à §Ó§Ö§Ý§Ú§Ü§Ñ §ã§Ý§à§Ó§Ñ. ID §Þ§à§â§Ñ §Õ§Ñ §Õ§Ö§æ§Ú§ß§Ú§ê§Ö §Ü§à§â§Ú§ã§ß§Ú§Ü §Ü§Ñ§Õ§Ñ §Þ§Ö?§Ñ §å§ã§Ý§à§Ó§Ö §æ§Ú§Ý§ä§Ö§â§Ñ, §Ñ§Ý§Ú ?§Ö §Ò§Ú§ä§Ú §Ô§Ö§ß§Ö§â§Ú§ã§Ñ§ß §Ú§Ù§ß§à§Ó§Ñ §Ü§Ñ§Õ§Ñ §Ú§ç §ß§Ñ§Ü§ß§Ñ§Õ§ß§à §Ù§Ñ§ç§ä§Ö§Ó§Ñ. |
operator | integer | §°§á§Ö§â§Ñ§ä§à§â §å§ã§Ý§à§Ó§Ñ. Property behavior: - §à§Ò§Ñ§Ó§Ö§Ù§ß§à §Ñ§Ü§à ?§Ö type §á§à§Õ§Ö§ê§Ö§ß §ß§Ñ "§ß§à§Ó§Ñ §Ô§â§å§á§Ñ §Õ§à§Þ§Ñ?§Ú§ß§Ñ §Õ§à§Ô§Ñ?§Ñ?§Ñ ", "§ã§ä§Ñ§â§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä §à§Ù§ß§Ñ§Ü§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ" §Ú§Ý§Ú "§Ó§â§Ö§Õ§ß§à§ã§ä §ß§à§Ó§Ö §à§Ù§ß§Ñ§Ü§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ" |
§¥§Ñ §Ò§Ú§ã§ä§Ö §Ò§à?§Ö §â§Ñ§Ù§å§Þ§Ö§Ý§Ú §Ü§Ñ§Ü§à §Õ§Ñ §Ü§à§â§Ú§ã§ä§Ú§ä§Ö §æ§Ú§Ý§ä§Ö§â§Ö §ã§Ñ §â§Ñ§Ù§Ý§Ú§é§Ú§ä§Ú§Þ §ä§Ú§á§à§Ó§Ú§Þ§Ñ §Ú§Ù§â§Ñ§Ù§Ñ, §á§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §á§â§Ú§Þ§Ö§â§Ö §ß§Ñ correlation.get §Ú correlation.create §ã§ä§â§Ñ§ß§Ú§è§Ñ§Þ§Ñ §Þ§Ö§ä§à§Õ§Ñ.
§³§Ý§Ö§Õ§Ö?§Ú §à§á§Ö§â§Ñ§ä§à§â§Ú §Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §ã§å §á§à§Õ§â§Ø§Ñ§ß§Ú §Ù§Ñ §ã§Ó§Ñ§Ü§Ú §ä§Ú§á §å§ã§Ý§à§Ó§Ñ.
|Condition|Condition name|Supported operators|Expected value| |--------|--------------|-------------------|---- ----------| |2|Host group|=, <>|ID §Ô§â§å§á§Ö §Õ§à§Þ§Ñ?§Ú§ß§Ñ.| |4|Old event tag value|=, <>, like, not like|string| |5|New event tag value|=, <>, like, not like|string|