Previous Menu Next
Engine Streams

By default, the engine has a single stream called default. Unless you specify otherwise, no additional streams are created and all correlation circuits are enabled on the default stream.

Additional streams may be created to provide specially correlated event streams to specific downstream applications. For example, a security alarm monitor may require a specially correlated event stream.

To create a new event stream, use the ecsmgr utility:

    ecsmgr -create_stream <streamName> <policy>

where:

<streamName>
is the name you want the stream known by
<policy>
is the policy for the stream and must be one of discard or output. If a policy is not specified it defaults to output.

The stream policy affects what happens to events that are not specifically correlated:

  • An output policy causes an event to be output, unless one or more of the circuits on that stream discards the event.
  • A discard policy causes an event to be discarded, unless one or more of the circuits on that stream outputs the event.

To enable and disable correlation circuits on a stream other than the default stream, you must specify the stream name. For example, to enable a previously loaded correlation circuit called myCircuit onto a previously created stream called myStream:

	ecsmgr -stream myStream -enable myCircuit