- Get Started with Threat Detection Management
-  Analytics Rules- Analytics Rule Classifications
- Create an Analytics Rule
- Manage Analytics Rules
- Tune Analytics Rules
- Share Analytics Rules
- Troubleshoot Analytics Rules
-  Analytics Rules Syntax- Advanced Analytics Rule Syntax vs. Analytics Rule Syntax
- Logical Expressions in Analytics Rule Syntax
- String Operations Using Analytics Rule Syntax
- Integer Operations Using Analytics Rule Syntax
- Time Operations Using Analytics Rule Syntax
- Network Operations Using Analytics Rule Syntax
- Context Operations Using Analytics Rule Syntax
- Entity Operations Using Analytics Rule Syntax
- Correlation Rule Operations Using Analytics Rule Syntax
 
- Analytics Engine Status
 
- Correlation Rules
- Threat Scoring
PrevNext
Clone a Correlation Rule
Clone an existing rule as a starting point for a new correlation rule.
- In Threat Detection Management, navigate to the Correlation Rules tab, then select a correlation rule to clone: - Click on a correlation rule, then click Clone.  
- For the correlation rule you're cloning, click the More menu  , then select Clone. , then select Clone.
 
- Name the new correlation rule. 
- Click Clone. The new correlation rule is created in Disabled status. To customize the rule, edit the correlation rule.