What is historical rule correlation?
When you create a rule in QRadar, you would like to test the rule against sample data to understand the number of offenses created, the frequency of the offensees, and the performance impact on the system. The best way to test this is to create a rule and then run a historical correlation to test the rule. The historical correlation rule is run on past data. We can select the range of time for which data was collected to run the rule. For example, a newly created rule can be run on 6-month-old data. Usually, you should run the historical correlation during non-business hours so that the impact, if any, is minimal. Based on the results, you can further tune the rule.
Consider another scenario in which QRadar was down for some time because of, say, a system upgrade activity or any other reason. In such a scenario, we can run a historical correlation and generate the offenses that were lost if there are any.
Historical correlation is also used...