Managing correlation rules
Note
This feature is in the Preview stage. To get access, contact tech support
This section describes how to create correlation rules, manage their settings, and perform basic operations with them.
Getting started
The Yandex SIEM section will appear in the Cloud Center interface as a Security Deck module after the access request is approved.
You need the ycem.editor role to use the service.
Creating a correlation rule
To create a correlation rule:
- Go to Security Deck
. - In the left-hand panel, select Yandex SIEM.
- Navigate to Correlation rules.
- Click New rule.
- In the Correlation condition field, enter your KQL query. Use templates, schema, or datasets as needed.
- Under Aggregation, specify the aggregation key and aggregation window.
- Under Actions on trigger, configure the new alert by setting its name, type, and classification.
- Under Parameters, fill in the required Name field, and, optionally, Description, Category, and Trigger severity.
- Click Save.
Editing a rule
To change edit a correlation rule:
- Go to Security Deck
. - In the left-hand panel, select Yandex SIEM.
- Navigate to Correlation rules.
- In the rule's row, click
and select Edit. - Edit the fields as needed.
- Click Save.
Disabling a rule
To disable a correlation rule:
- Go to Security Deck
. - In the left-hand panel, select Yandex SIEM.
- Navigate to Correlation rules.
- In the rule's row, click
and select Disable.
A disabled rule changes its status to Inactive and stops processing events.
Resetting changes
To reset the changes you made to the rule to the last deployed version:
- Go to Security Deck
. - In the left-hand panel, select Yandex SIEM.
- Navigate to Correlation rules.
- In the rule's row, click
and select Reset changes.
All unsaved changed will be canceled. The rule will reset to the last deployed configuration.
Deleting a rule
You can only delete custom rules. You cannot delete preset rules.
To delete a custom correlation rule:
- Go to Security Deck
. - In the left-hand panel, select Yandex SIEM.
- Navigate to Correlation rules.
- In the rule's row, click
and select Delete. - Confirm the deletion.
Warning
Deleting a rule is irreversible. All rule settings will be deleted.