Skip to content

Examples of Correlations #4109

Closed Answered by nasbench
joshnck asked this question in Q&A
Mar 14, 2023 · 1 comments · 2 replies
Discussion options

You must be logged in to vote

Hi,

The SIGMA V2 correlation "proposal" is still a work in progress and shouldn't be used in production. The main rule repo isn't using the new correlation and we've deprecated the older correlation rules as we're transitioning to PySIGMA. Also, this feature is not yet implemented in PySIGMA and it's still under construction and discussion :)

Now to answer your question about how it works. (this could and will change in the future).

Basically there are many correlation types and depending on the type of correlation some fields will be required or added.

In the example, you linked it's a value_count correlation rule. So it needs a field to count on and a grouping designated by the group-by

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@joshnck
Comment options

@nasbench
Comment options

Answer selected by joshnck
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants