![]() |
![]() |
![]() |
Tutorial 4: Correlation engine primer Mon, 10 Dec 2007 Introduction
In order to answer to a recent forum post I had to do a quick research since it had been some time since I last tested this. Hello, Is there a document talking about how the directives are processed? One question that I have is if you have multiple directives created and an event comes in that matches the initial states of more than a single directive will both actually process the event, or only the first match (which I think is the case)? Thanks for any clarification you can provide. Stephen This post gives a bit of insight to how the correlation engine works and features some simple, custom made directives that help me answer that question. The test environment features two events belonging to the ssh plugin (plugin_id 4003):
::read more
posted at: 12:47 | path: /ossim/tutorials | permanent link to this entry | 3 comments | |
Categories
/ (37)
Archives
2008-Dec Tags | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
![]() |
![]() |




