- Get Started with Threat Detection Management
- Analytics Rules
- Analytics Rule Classifications
- Create an Analytics Rule
- Manage Analytics Rules
- Tune Analytics Rules
- Find Analytics Rules
- Share Analytics Rules
- Troubleshoot Analytics Rules
- Analytics Rules Syntax
- Advanced Analytics Rule Syntax vs. Analytics Rule Syntax
- Logical Expressions in Analytics Rule Syntax'
- String Operations Using Analytics Rule Syntax
- Integer Operations Using Analytics Rule Syntax
- Time Operations Using Analytics Rule Syntax
- Network Operations Using Analytics Rule Syntax
- Context Operations Using Analytics Rule Syntax
- Entity Operations Using Analytics Rule Syntax
- Correlation Rule Operations Using Analytics Rule Syntax
- Analytics Engine Status
- Correlation Rules
- Correlation Rule Sequences
- Correlation Rules Templates
- Create Correlation Rules
- Create a Correlation Rule Using the Exabeam Nova Rule Creator
- Create a Correlation Rule from Scratch Using the Manual Rule Creator
- Create a Correlation Rule from a Template
- Create a Correlation Rule from Search
- Group by Field in Correlation Rules
- Detect Absent Events or Fields Using Correlation Rules
- Granular Suppression
- Correlation Rule Evaluation Delay
- Manage Correlation Rules
- Find Correlation Rules
- Share Correlation Rules
- View Correlation Rules Metrics
- Threat Scoring
- Get Notified About Threat Detection Management
Network Operations Using Analytics Rule Syntax
Evaluate IP addresses, hosts, and domains using analytics rule syntax.
IP Address Operations
Evaluate IP addresses in your network.
Function | Description | Returned Value | Examples |
|---|---|---|---|
| Checks if | Boolean |
|
| Checks if | Boolean |
|
| Checks if | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if the event contains geo-information Valid arguments for
| Boolean |
|
| Retrieves geo-information Valid arguments for
| String |
|
Client and Host Operations
Evaluate clients and hosts in your network.
Function | Description | Returned Value | Examples |
|---|---|---|---|
| COMING SOON | Boolean | COMING SOON |
| Extracts the operating system from user agent | String |
|
| Extracts the browser from user agent | String |
|
| Checks whether host name
| Boolean |
|
Web Domain Operations
Evaluate web domains.
Function | Description | Returned Value | Examples |
|---|---|---|---|
| Checks if domain
| Boolean |
|
| Retrieves a list of all threats associated with domain | String | returns COMING SOON |
| Extracts the domain from | String |
|
| Extracts the domain from | String |
|
| Checks whether a second-level domain
| Boolean |
|