Skip to main content

Threat CenterThreat Center Guide

Table of Contents

Pre-Built Detection Grouping Rules

To ensure alerts and cases always contain meaningful information, pre-built detection grouping rules group detections without you having to create or customize your own rules.

Pre-built detection grouping rules are detection grouping rules that are already configured and enabled by default. If you don't want to use these pre-built detection grouping rules, create your own rules from scratch or clone a pre-built detection grouping rule to use as a starting point for a new rule.

Rule is always enabled and the last rule in the sequence. You can't disable or reorder it. You can disable and reorder all other pre-built detection grouping rules. You can't delete any pre-built detection grouping rule.

The pre-built detection grouping rules available to you differ based on your license:

Pre-Built Detection Grouping Rules in the New-Scale Analytics and New-Scale Fusion Licenses

If you have the New-Scale Analytics license or New-Scale Fusion license, there are seven pre-built detection grouping rules that are, by default, in the following order:

  1. Source User Entity – If the detection is associated with a source user entity, the detection is grouped by source user entity.

  2. Destination User Entity – If the detection is associated with a destination user entity, the detection is grouped by destination user entity.

  3. Source Device Entity – If the detection is associated with a source device entity, the detection is grouped by source device entity.

  4. Destination Device Entity – If the detection is associated with a destination device entity, the detection is grouped by destination device entity.

  5. Src Ip – If the detection src_ip attribute has a value, the detection is grouped by source IP address.

  6. Dest Ip – If the detection dest_ip attribute has a value, the detection is grouped by destination IP address.

  7. Rule – If the detection rulename attribute has a value, the detection is grouped by rule name.

Pre-Built Detection Grouping Rules in the New-Scale SIEM License, Exabeam Security Operations Licenses, and Fusion Licenses

If you have the New-Scale SIEM license or any of the Exabeam Security Operations or Fusion licenses, there are six pre-built detection grouping rules that are, by default, in the following order:

  1. User – If the detection is associated with one unique user, it's grouped by user.

  2. Src Host – If the detection src_host attribute has a value, the detection is grouped by source host.

  3. Dest Host – If the detection dest_host attribute has a value, the detection is grouped by destination host.

  4. Src Ip – If the detection src_ip attribute has a value, the detection is grouped by source IP address.

  5. Dest Ip – If the detection dest_ip attribute has a value, the detection is grouped by destination IP address.

  6. Rule – If the detection rulename attribute has a value, the detection is grouped by rule name.