- Get Started with Threat Center
- Group Detections
- Work on Cases
- Triage Alerts in Threat Center
- Edit and Collaborate in Threat Center
- Find Cases or Alerts
- Build a Search in Threat Center
- Enter a Search Using Exabeam Query Language in Threat Center
- Enter a Search Using Natural Language in Threat Center
- Run a Recent Search in Threat Center
- Create a New Saved Search in Threat Center
- Run a Saved Search in Threat Center
- Edit a Saved Search in Threat Center
- Delete a Saved Search in Threat Center
- Sort Cases or Alerts
- View Case and Alert Metrics
- Get Notified About Threat Center
PrevNext
Clone a Detection Grouping Rule
Clone a detection grouping rule as a starting point for a new detection grouping rule.
In Threat Center, click Settings, then navigate to the Detection grouping rules tab.
For a detection grouping rule, click the More menu , then select Clone.
The cloned rule is created. – <number> is appended to its name, depending on how many clones you've created.
To continue customizing the rule, edit the rule.