A **Correlation Search** continuously evaluates data against a set of predefined conditions. When the conditions are met, it triggers one or more actions (like creating a Notable Event or adding to a Risk score).
Unlike standard alerts, Correlation Searches are tightly integrated with the ES framework, automatically populating fields like urgency, risk object, and providing drill-down search capabilities.
| tstats count from datamodel=Authentication where Authentication.action="failure" by Authentication.user | where count > 10