‎2012-05-09
05:24 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Correlation Classes - What's the point?
I am wondering if there is any benefit to creating my own set of correlation classes as opposed to just using the ones built in. It seems you can only have one of four pre-defined types anyway (Security, Host, Network, Storage). I am just not even sure why this functionality exists.
If you have done anything interesting or useful with correlation classes I would certainly like to hear about it! Thank you!
2 Replies
‎2012-05-10
11:16 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I think they may have had some other intent when they were first introduced a long time ago, but you're right, they don't do much. I use them sheerly for organization purposes... like setting up folders in a file system. I create new classes based on groups or themes for my rules, just to make them easier to find when it comes time to put them into a view.
‎2012-05-10
12:12 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks, that is kind of what I thought. I created versions for our different companies, but I have not found them to be a huge benefit so far.
