Skip to main content

Threat CenterThreat Center Guide

Table of Contents

Pre-Built Detection Grouping Rules

To ensure alerts and cases always contain meaningful contextual information, pre-built detection grouping rules group detections without you having to create or customize your own rules.

Pre-built detection grouping rules are detection grouping rules that are already configured and enabled by default. There are six pre-built detection grouping rules that are, by default, in the following order:

  1. User – If the detection is associated with one unique user, it's grouped by user.

  2. Src Host – If the detection src_host attribute has a value, the detection is grouped by source host.

  3. Dest Host – If the detection dest_host attribute has a value, the detection is grouped by destination host.

  4. Src IP – If the detection src_ip attribute has a value, the detection is grouped by source IP address.

  5. Dest IP – If the detection dest_ip attribute has a value, the detection is grouped by destination IP address.

  6. Rule – If the detection rulename attribute has a value, the detection is grouped by rule name.

Rule is always enabled and the last rule in the sequence. You can't disable or reorder it.

You can disable and reorder all other pre-built detection grouping rules. You can't delete any pre-built detection grouping rule.

If you don't want to use these pre-built detection grouping rules, create your own rules from scratch or clone a pre-built detection grouping rule to use as a starting point for a new rule.