Any word on this?
Short version: you can have multiple thresholds in different groups (and around the entire correlation) and events within the correlation can happen out of order.
Rather than saying IF this THEN this THEN this, you say IF this AND this AND this, and those events all have to happen within some window of each other - either before OR after (globally, this is the response window; if a threshold is specified it's the correlation time).
And, rather than saying "if 5 of these occur, do this" then building a second rule for "also if 5 of these other things occur, do this", you can do all of that in ONE correlation rule with groupings.
Let me know if you'd like more examples or detail.
Thanks for the explanation, it's exactly what I was looking for!