Previous Topic: Rule Test Interface Does Not Show Completed State

Next Topic: Event Refinement

Time Fields Treated Differently in Correlation Rule Test

Symptom:

Under certain narrow circumstances, testing of correlation rules returns different results than live correlation. This occurs under the following conditions:

In this case the rule test service derives the event time fields using the Event Log Store time zone, rather than the originating time zone of the event. This may result in the tested rule incorrectly identifying whether the event matches the rule qualifications.

Solution:

This behavior only occurs when testing a rule. In live correlation, the service properly uses the originating time zone of the event when deriving time fields.