Symptom:
Under certain narrow circumstances, testing of correlation rules returns different results than live correlation. This occurs under the following conditions:
In this case the rule test service derives the event time fields using the Event Log Store time zone, rather than the originating time zone of the event. This may result in the tested rule incorrectly identifying whether the event matches the rule qualifications.
Solution:
This behavior only occurs when testing a rule. In live correlation, the service properly uses the originating time zone of the event when deriving time fields.
| Copyright © 2010 CA. All rights reserved. | Email CA Technologies about this topic |