Skip to main content

Threat CenterThreat Center Guide

Table of Contents

Create a Detection Grouping Rule

Create a detection grouping rule to group related detections according to criteria you specify.

You can create up to 20 detection grouping rules.

  1. In Threat Center, click Settings, then navigate to the Detection grouping rules tab.

    Link to Threat Center settings highlighted in a red rectangle.
  2. Click + New Rule.

  3. In New Detection Name, enter the rule name. You can't rename the rule after you save it.

  4. Under Trigger, select Select trigger, then select is created.

  5. Under Condition, define the conditions a detection must satisfy for the rule to apply to the detection. If you're grouping a detection by a certain field, one of the conditions must be that the field exists to ensure the detection contains the field and preserve the grouping logic; for example, if you're grouping detections by field Src Ip, one of the conditions must be Src Ip exists.

    1. Click Select object, then select a field from the list.

    2. Click Select condition, then select an operator from the list. Depending on the operator you select, you may need to enter a value.

    3. (Optional) To add additional conditions, click threatcenter-detectiongroupingrule-createrule-add.png. All conditions must be satisfied for the rule to apply to the detection.

  6. Under Action, define by which fields a detection is grouped. Click Select field, then select a field from the list. If not already defined, Threat Center adds the condition <field> exists. To group the detection by an additional field, click threatcenter-detectiongroupingrule-createrule-add.png.

  7. Click Save.