Skip to main content

Responses are generated using AI and may contain mistakes.

Threat Detection ManagementThreat Detection Management Guide

Create an Analytics Rule Using Exabeam Nova Rule Creator

Create an analytics rule by prompting Exabeam Nova with natural language descriptions of the analytics rule you want to create.

  1. In the Analytics Rule tab, click + New Rule, then select Exabeam Nova Rule Creator.

  2. In Describe the rule you want to create, enter a natural language description of the analytics rule you want to create. For best results, ensure that you mention:

    • The activity the analytics rule detects; for example, abnormal inbound network activity traffic or malicious IIS module installation

    • The conditions that trigger the analytics rules; for example, appcmd.exe is run to install or add an IIS native-code module

    • The time frame of the trigger activity; for example, total bytes in per source IP exceeding 500 MB in a one-day window

    • Any conditions that suppress the analytics rule from triggering; for example, when other analytics rules trigger or a specific field value.

    To help you get started, Exabeam Nova Rule Creator lists a number of clickable example prompts. When you click on an example prompt, it automatically populates the text input box, which you can then send to Exabeam Nova or customize.

  3. To send the description to Exabeam Nova Rule Creator, click A blue square with a white outline of a paper airplane in the center.. Exabeam Nova Rule Creator validates whether your description meets analytics rule field requirements, then generates a draft of the analytics rule.

  4. Review the analytics rule draft. To continue tuning the analytics rule, continue prompting Exabeam Nova Rule Creator with the changes you want to see in the analytics rule.

    You can also ask Exabeam Nova Rule Creator other questions about Threat Detection Management and analytics rules; for example, what the different analytics rule types are, or what an analytics rule field does.

  5. To create the analytics rule, click Create Rule.