Correlations

Related alerts clustered into one story, with entity risk.

What a correlation is

Correlation runs alongside detection. It looks at recent alerts, links those that share entities such as a host, a user or an address, and writes clusters of two or more alerts as correlations. A correlation has a deterministic identifier anchored to its oldest member, so it grows as new alerts join instead of being recreated.

Entities that appear on very many alerts, typically a domain controller or a proxy, are treated as hubs, so correlations stay focused on genuinely related alerts.

Entity risk

Each entity accumulates a risk score from the alerts it appears on: severity-weighted, decaying over time, amplified when different rules and different sources agree. The Correlations page lists the riskiest entities in your scope with the alerts behind the number.

Working a correlation

Open a correlation to see its members on one timeline and one graph. From there:

  • Escalate to case: creates a case with every member alert attached.
  • Close all: closes the members with one disposition.
  • Open any member to work it individually.

Incidents

In the console, incident means a case and nothing else. Correlations are the clustering layer; cases are the workspace.