What kind of correlation rules is possible create on ES?

I need monitor and correlate alarms. Is it possible create this kind of correlations:

  • deduplication
  • Problem/resolution correlation
  • Work in real-time and time window grouping
  • Topology-based correlation
  • Identify sequence of events and patterns

When the system receives a problem alarm, if this alarm won't receive the resolution alarm in 5 minutes, create a incident on ITSM solution.

Use a topology to identify a RCA.

