Create an Event Supervised Correlation Policy

post

/api/event/SupervisedCorrelations/

Creates a new event supervised correlation policy.
The minimum required properties in the request body are:
  • SupervisedCorrelationName
  • MatchFields
  • RootMatchOperators
  • SymptomMatchOperators
  • MetaEventID
  • GroupByFields
  • MinimumMembers
  • TimeWindow
You must also include properties for the field set in MatchFields as <Field> and <Field>Root. For example, if you set the value of MatchFields to ["Ack"], you must also include AckRoot and Ack. The RootMatchOperators values are applied to the corresponding root cause field by array index. The SymptomMatchOperators values are applied to the corresponding symptom field by array index. The legacy MatchOperators property is accepted as an alias for RootMatchOperators.

Request

There are no request parameters for this operation.

Supported Media Types
Request Body - application/json ()
Root Schema : schema
Type: object
Show Source
Nested Schema : MatchFields
The event fields that must have matching values to fit the cluster
Match One Schema
Show Source
Example:
SubNode
Nested Schema : MatchOperators
Legacy root cause operator property. Use RootMatchOperators for new integrations.
Match One Schema
Show Source
Example:
=
Nested Schema : MetaEventID
Meta event to create as the root cause
Match One Schema
Show Source
Example:
1
Nested Schema : RootMatchOperators
The root cause operators for the match fields, in the same order as MatchFields
Match One Schema
Show Source
Example:
=
Nested Schema : SymptomMatchOperators
The symptom operators for the match fields, in the same order as MatchFields
Match One Schema
Show Source
Example:
=
Nested Schema : MatchFields-oneOf[0]
Type: array
Nested Schema : MatchOperators-oneOf[0]
Type: array
Show Source
  • Allowed Values: [ "=", "!=", ">", ">=", "<", "<=", "LIKE", "NOT LIKE", "REGEXP", "NOT REGEXP" ]
Nested Schema : RootMatchOperators-oneOf[0]
Type: array
Show Source
  • Allowed Values: [ "=", "!=", ">", ">=", "<", "<=", "LIKE", "NOT LIKE", "REGEXP", "NOT REGEXP" ]
Nested Schema : SymptomMatchOperators-oneOf[0]
Type: array
Show Source
  • Allowed Values: [ "=", "!=", ">", ">=", "<", "<=", "LIKE", "NOT LIKE", "REGEXP", "NOT REGEXP" ]
Back to Top

Response

Supported Media Types

200 Response

Successful operation
Body ()
Root Schema : schema
Match All
Show Source
Nested Schema : SuccessfulAddOperation
Type: object
The response body for a successful add operation.
Show Source
Nested Schema : type
Type: object
Show Source
Nested Schema : data
Type: array
The properties of the new event supervised correlation policy.
Show Source
Nested Schema : eventSupervisedCorrelationsRead
Type: object
Show Source
Nested Schema : MatchFields
The event fields that must have matching values to fit the cluster
Match One Schema
Show Source
Example:
SubNode
Nested Schema : MatchFieldValues
The values of the match fields
Match One Schema
Show Source
Example:
test
Nested Schema : MatchOperators
Legacy root cause operator property. Use RootMatchOperators for new integrations.
Match One Schema
Show Source
Example:
=
Nested Schema : MetaEventID
Meta event to create as the root cause
Match One Schema
Show Source
Example:
1
Nested Schema : RootMatchOperators
The root cause operators for the match fields, in the same order as MatchFields
Match One Schema
Show Source
Example:
=
Nested Schema : SymptomMatchOperators
The symptom operators for the match fields, in the same order as MatchFields
Match One Schema
Show Source
Example:
=
Nested Schema : MatchFields-oneOf[0]
Type: array
Nested Schema : MatchFieldValues-oneOf[0]
Type: array
Nested Schema : MatchOperators-oneOf[0]
Type: array
Show Source
  • Allowed Values: [ "=", "!=", ">", ">=", "<", "<=", "LIKE", "NOT LIKE", "REGEXP", "NOT REGEXP" ]
Nested Schema : RootMatchOperators-oneOf[0]
Type: array
Show Source
  • Allowed Values: [ "=", "!=", ">", ">=", "<", "<=", "LIKE", "NOT LIKE", "REGEXP", "NOT REGEXP" ]
Nested Schema : SymptomMatchOperators-oneOf[0]
Type: array
Show Source
  • Allowed Values: [ "=", "!=", ">", ">=", "<", "<=", "LIKE", "NOT LIKE", "REGEXP", "NOT REGEXP" ]

Default Response

Failed operation
Body ()
Root Schema : schema
Type: object
Show Source
Nested Schema : errors
Type: array
The list of errors reported. Validation errors will be keyed by record field.
Show Source
Nested Schema : items
Type: object
An error.
Back to Top