‎2012-01-04
10:04 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Decay Time
Hi All, Please explain the Use of Decay time in Correlation rule.
7 Replies
‎2012-01-04
10:10 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Decay Time is an overall "Time to Live" for the rule. If all the criteria of the rule are not met within the defined decay time, the running instance of the rule will expire and no alert will be generated. The Decay Time must be set to slightly exceed the span of all other timers built into the rule -so for example if you have a threshold built into the rule that looks for a sequence of events to happen in 60 seconds, you must set your decay time to be 61 seconds or more.
‎2012-01-06
06:08 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks Matt. I have a doubt on this.... Please consider the below example and provide your comments. For a rule if a condition is 5 events in 60 mins... decay time 61 mins.. For example: from 9:30 to 10:30 we have 4 events(9:30, 9:40,9:55,10:30) and other 2 events at 10:35 and 10:40. Will the alert trigger for this since alert criteria is met from 9:40 to 10:40... If yes, how the decay time will function in maintaining the events...
‎2012-01-06
08:20 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
No, it would not trigger. The decay timer starts ticking based based on the first matching event for that instance of the rule. Although events #2-6 constitute what would have been successful criteria for the alert, events #1-5 did not.
‎2012-01-06
08:29 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Matt, You mean to say even if the criteria met and alert will not trigger for events from 2-6.... As my rule should fire 5 events in 1 hour... What will be the resolution for above case... Regards, Vel
‎2012-01-06
08:41 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Correct. Although you do have an actual sequence of 5 events that did occur within a 1 hour timeframe, because the decay time triggers off of the first event no alert will fire (the rule expires before we ever get to event #5). What you are asking for is a perpetual start of a new decay timer every time a matching event is triggered, effectively launching an instance of a rule for every event. If you require this functionality, I would contact support and make an enhancement request.
‎2012-01-06
08:57 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks...
‎2012-01-25
05:58 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Velm, let me know if you have an RFE for this.
