In Helix, incoming events are tested against rules, and if the conditions of the rule are met it triggers an alert. There are different conditions you can use in a rule to test against incoming events: fields, correlation, deviation, and cardinality.
All rules start with the global parameters that define the rule: id, version, and name. The rule continues with a correlation conditions, which define the criteria for the rule to trigger an alert. This consists of one or more items that must be matched and correlated for the rule to fire.
Rules can test for specific values in individual event fields. For example, a rule could look for the srcipv4 field to equal the fixed address 10.0.0.1: srcipv4==10.0.0.1. You can use Boolean operators, for example or and and, to build more complex rules. In addition to testing fields in a single event, you can use rules to correlate between events. A correlation groups events together that have the same value for one or more defined fields. For example, the rule could look for a certain number of failed log on attempts from the same source IP address. The rule groups events by each unique IP address, and triggers if any of the groups reaches threshold you define, for example, ten failed log on attempts in a minute.
Rules are written in YAML and have the following parameters:
Name | Type | Required | Default | Description |
|---|---|---|---|---|
id | String | Yes | Not applicable | The unique identifier for the rule. |
name | String | Yes | Not applicable | The name of the rule. |
version | Number | Yes | Not applicable | The version of the rule. If you edit the rule, the version number is incremented. |
output | List<Output> | No | Not applicable | An optional list of field values to add to the alert generated by the rule. |
metadata | Object | No | Not applicable | An optional object consisting of name/value pairs to associate with the rule. |