QRadar: Why are Offenses generated from Historical Correlation named strangely

When I generate Offenses using a Historical Correlation profile, why don't I get the Offense names I expect?


Offenses generated during a Historical Correlation run are named with the low-level category of the first triggering event.

When events match a Rule during a Historical Correlation run, the only action taken by the system will be to generate an Offense if the Rule is configured to do so. All additional actions and responses will be ignored, including the generation of Custom Rule Engine events configured to contribute to Offense naming.

Modified date:
26 June 2020