KQL Comprehensive Tutorial on Event Correlation Rules

I need to build some rather complex rules, but I'm just getting started with KQL. I haven't found any in-depth comprehensive tuts out there on event correlation. Everything is always brief and basic. Anyone know of any good resource?

Thanks for chiming in!

You can use EQL EQL syntax reference | Elasticsearch Guide [8.5] | Elastic for event mapping. Take a look at these links:

1 Like

Thank you! That was really helpful!

1 Like

Fyi https://www.elastic.co/en/security-labs/handy-elastic-tools-for-the-enthusiastic-detection-engineer

gives me a 404

Guessing you mean