Skip to main content

Responses are generated using AI and may contain mistakes.

Threat CenterThreat Center Guide

Table of Contents

Create Standalone Cases from Correlation Rules Using a Detection Grouping Rule

To identify Threat Center cases created as the outcome of a correlation rule, create a detection grouping rule that groups a correlation rule detection into a standalone case.

For a standalone case to be created, the detection grouping rule must be first in the list of detection grouping rules.

  1. In Threat Center, click Settings, then navigate to the Detection grouping rules tab.

    Link to Threat Center settings highlighted in a red rectangle.
  2. Click + New Rule.

  3. In New Detection Name, enter the rule name. You can't rename the rule after you save it.

  4. Under Trigger, select Select trigger, then select is created.

  5. Under Condition, you define the conditions a detection must satisfy for the rule to apply to the detection. All conditions must be satisfied for the rule to apply to the detection. To define multiple conditions, click threatcenter-detectiongroupingrule-createrule-add.png.

    To create standalone cases from correlation rules, define the following conditions:

    • Rule Source is equals to Correlation Rule:

      1. Click Select object, then select Rule Source.

      2. Click Select condition, then select is equals to.

      3. Click Enter value, then enter Correlation Rule.

    • Rule Name exists:

      1. Click Select object, then select Rule Name.

      2. Click Select condition, then select exists.

    • GroupBy field exists:

      1. Click Select object, then select GroupBy field.

      2. Click Select condition, then select exists.

    • Create Case is equals to true:

      1. Click Select object, then select Create Case.

      2. Click Select condition, then select is equals to.

      3. Click Enter value, then enter true.

  6. Under Action, you define the fields by which a detection is grouped. To define multiple actions, click threatcenter-detectiongroupingrule-createrule-add.png.

    To create standalone cases from correlation rules, define actions that group detections by rule name and group by field:

    • To group detections by rule name, click + Field, then select Rule Name.

    • To group detections by group by field, click + Field, then select GroupBy field.

  7. Click Save. Ensure that the detection grouping rule is ordered first in the list.