Skip to content

Commit

Permalink
Improve doc concerning similarity strategy with sigma correlation rule
Browse files Browse the repository at this point in the history
  • Loading branch information
Charles Ngor committed Feb 12, 2024
1 parent cb7e328 commit 66244a5
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions docs/xdr/features/detect/rules_catalog.md
Original file line number Diff line number Diff line change
Expand Up @@ -175,6 +175,10 @@ You can select these event fields in your rule configuration. To do so, click on

In addition to that, these event fields can be added to the `Swappable fields`. A typical example of that is `source.ip` and `destination.ip`.

!!! warning
Custom similarity strategy are not supported with Sigma Correlation rules.
Fields used in the `group-by` clause of the pattern will be used as similarity strategy.

!!! note
You can learn more about similarity strategies in this [section](../../investigate/alerts/#similarity-strategies).

Expand Down

0 comments on commit 66244a5

Please sign in to comment.