Skip to main content

Correlation RulesCorrelation Rules Guide

Test a Correlation Rule

To test a correlation rule and ensure it works as you expect, enable the rule in test mode.

In test mode, the rule triggers but the outcomes you specified are suppressed. An event with activity type rule-trigger-test is created. Threat Center doesn't create an alert. The rule status is changed to Testing.

  1. Create or edit a rule.

  2. Under the Review & Save step, toggle Enable Rule on, then select Test Mode.

  3. Click Save.