Any suggestions on how to configure the correlation search schedule in a way that will not be affected by a maintenance downtime ?
For example if you have a correlation search that is schedule to run every hour at minute 5 for the last hour . how can be configured to cover also the skipped run and to not miss alerts?
Can you do your correlation search over a couple of hours bucketed by hour, then append the previous results and remove duplicates?
thanks for the reply.
please can you provide an example how to configure the cs and how to exclude duplicates?