- Get Started with Threat Detection Management
- Analytics Rules
- Analytics Rule Classifications
- Create an Analytics Rule
- Manage Analytics Rules
- Tune Analytics Rules
- Share Analytics Rules
- Troubleshoot Analytics Rules
- Analytics Rules Syntax
- Advanced Analytics Rule Syntax vs. Analytics Rule Syntax
- Logical Expressions in Analytics Rule Syntax
- String Operations Using Analytics Rule Syntax
- Integer Operations Using Analytics Rule Syntax
- Time Operations Using Analytics Rule Syntax
- Network Operations Using Analytics Rule Syntax
- Context Operations Using Analytics Rule Syntax
- Entity Operations Using Analytics Rule Syntax
- Correlation Rule Operations Using Analytics Rule Syntax
- Analytics Engine Status
- Correlation Rules
- Threat Scoring
Create an Analytics Rule
Create analytics rules to address specific security threats unique to your environment.
There are two ways to create an analytics rule: using a point-and-click interface directly in Threat Detection Management; or by defining the analytics rule configuration in a JSON file, then importing the JSON file into Threat Detection Management.
You can create an unlimited number of analytics rules, but there is a limit to the number of custom analytics rules you're allowed to enable.
Create Analytics Rules Using a Builder
Create an analytics rule using a point-and-click builder directly in Threat Detection Management.
Create an Analytics Rule using JSON
Create analytics rules by defining the analytics rule configuration in a JSON file, then importing the JSON file into Threat Detection Management.