- play_arrow What's New for JSA Users
- play_arrow Capabilities in your JSA product
- play_arrow Dashboard Management
- Dashboard Management
- Default Dashboards
- Custom Dashboards
- Creating a Custom Dashboard
- Using the Dashboard to Investigate Log or Network Activity
- Configuring Dashboard Chart Types
- Removing Dashboard Items
- Detaching a Dashboard Item
- Renaming a Dashboard
- Deleting a Dashboard
- Managing System Notifications
- Adding Search-based Dashboard Items to the Add Items List
- play_arrow QRadar Analyst Workflow
- play_arrow Offense Management
- play_arrow Log Activity Investigation
- play_arrow Network Activity Monitoring
- play_arrow Asset Management
- play_arrow Chart Management
- play_arrow Event and Flow Searches
- play_arrow Custom Event and Flow Properties
- play_arrow Rules
- play_arrow Juniper Networks X-Force Integration
- play_arrow Report Management
Creating a Historical Correlation Profile
You create a historical correlation profile to rerun past events and flows through the custom rules engine (CRE). The profile includes information about the data set and the rules to use during the run.
You can create historical profiles only in JSA. You cannot create historical profiles in Log Manager.
Common rules test data in both events and flows. You must have permission to view both events and flows before you can add common rules to the profile. When a profile is edited by a user who doesn't have permission to view both events and flows, the common rules are automatically removed from the profile.
You can configure a profile to correlate by either start time or device time. Start time is the time when the events arrive at the event collector. Device time is the time that the event occurred on the device. Events can be correlated by start time or device time. Flows can be correlated by start time only.
You can include disabled rules in the profile. Rules that are disabled are indicated in the rules list with (Disabled) after the rule name.
A historical correlation run does not contribute to a real-time offense, nor does it contribute to an offense that was created from an earlier historical correlation run, even when the same profile is used.
If you create too many historical correlation profiles that have many rules that are assigned to them, your offenses can be slow to load. If your offenses are slow to load, you can either delete unneeded profiles or edit them to have fewer rules.