You can now use the Sigma Correlations format when creating rules!
This will allow you to build detection logic acting on more than one event using the following correlation types:
⚡Just like any Sigma rule, Sigma Correlation rules are applied to the event stream in real-time.
Here is an example of a rule using Sigma Correlations:
If you want to learn more, have a look at the documentation