- Get Started with Threat Center
- Threat Center
- Threat Center Permissions
- Threat Center Alerts: Read
- Threat Center Alerts: Read, Write, and Delete
- Threat Center Cases: Read
- Threat Center Cases: Read, Write, and Delete
- Threat Center Detection Grouping Rules: Read
- Threat Center Detection Grouping Rules: Read, Write, and Delete
- Threat Center Watchlist: Read
- Threat Center Watchlist: Read, Write, and Delete
- Threat Center Cases
- Threat Center Alerts
- Threat Center Detections
- Threat Center Risk Score
- Monitor Entities of Interest in Threat Center
- Group Detections
- Work on Cases
- Work on Alerts
- Edit and Collaborate in Threat Center
- Use Automation Tools in Threat Center
- Find Cases and Alerts
- Sort Cases or Alerts
- Filter Cases or Alerts
- Search for Cases or Alerts in Threat Center
- Build a Search in Threat Center
- Enter a Search Using Exabeam Query Language in Threat Center
- Enter a Search Using Natural Language in Threat Center
- Run a Recent Search in Threat Center
- Create a New Saved Search in Threat Center
- Run a Saved Search in Threat Center
- Edit a Saved Search in Threat Center
- Delete a Saved Search in Threat Center
- View Case and Alert Metrics
- Get Notified About Threat Center
- Threat Center APIs
Pre-Built Detection Grouping Rules
To ensure alerts and cases always contain meaningful information, pre-built detection grouping rules group detections without you having to create or customize your own rules.
Pre-built detection grouping rules are detection grouping rules that are already configured and enabled by default. If you don't want to use these pre-built detection grouping rules, create your own rules from scratch or clone a pre-built detection grouping rule to use as a starting point for a new rule.
Rule is always enabled and the last rule in the sequence. You can't disable or reorder it. You can disable and reorder all other pre-built detection grouping rules. You can't delete any pre-built detection grouping rule.
The pre-built detection grouping rules available to you differ based on your license:
Pre-Built Detection Grouping Rules in the New-Scale Analytics and New-Scale Fusion Licenses
If you have the New-Scale Analytics license or New-Scale Fusion license, there are seven pre-built detection grouping rules that are, by default, in the following order:
Source User Entity – If the detection is associated with a source user entity, the detection is grouped by source user entity.
Destination User Entity – If the detection is associated with a destination user entity, the detection is grouped by destination user entity.
Source Device Entity – If the detection is associated with a source device entity, the detection is grouped by source device entity.
Destination Device Entity – If the detection is associated with a destination device entity, the detection is grouped by destination device entity.
Src Ip – If the detection
src_ip
attribute has a value, the detection is grouped by source IP address.Dest Ip – If the detection
dest_ip
attribute has a value, the detection is grouped by destination IP address.Rule – If the detection
rulename
attribute has a value, the detection is grouped by rule name.
Pre-Built Detection Grouping Rules in the New-Scale SIEM License, Exabeam Security Operations Licenses, and Fusion Licenses
If you have the New-Scale SIEM license or any of the Exabeam Security Operations or Fusion licenses, there are six pre-built detection grouping rules that are, by default, in the following order:
User – If the detection is associated with one unique user, it's grouped by user.
Src Host – If the detection
src_host
attribute has a value, the detection is grouped by source host.Dest Host – If the detection
dest_host
attribute has a value, the detection is grouped by destination host.Src Ip – If the detection
src_ip
attribute has a value, the detection is grouped by source IP address.Dest Ip – If the detection
dest_ip
attribute has a value, the detection is grouped by destination IP address.Rule – If the detection
rulename
attribute has a value, the detection is grouped by rule name.