Skip to main content

Responses are generated using AI and may contain mistakes.

Threat Detection ManagementThreat Detection Management Guide

Edit an Analytics Rule

Edit a custom analytics rule you created.

You can edit custom analytics rules only. You can't edit pre-built analytics rules.

If an enabled analytics rule has a required training period, editing the rule doesn't reset its training. The only way to reset the training for an analytics rule is to disable the rule.

There are two ways to edit analytics rule: using Exabeam Nova Rule Creator or manually.

Edit an Analytics Rule Using Exabeam Nova Rule Creator

Send natural language prompts to Exabeam Nova Rule Creator describing the changes you want to make to the analytics rule. Exabeam Nova Rule Creator drafts the changes, which you can review before saving.

  1. For the custom analytics rule you're editing:

    • Click the More menu The more options menu; three vertical dark grey dots on an off-white background., then select Edit.

    • Right-click the analytics rule, then select Edit.

    • Select the checkbox for the analytics rule, then select Edit.

    • Select the analytics rule to view its details, then select Edit.

  2. Next to Exabeam Nova can help you edit or update rules, click Edit.

  3. In Describe the rule you want to create, enter a natural language description of the change you want to make.

  4. To send the description to Exabeam Nova Rule Creator, click A blue square with a white outline of a paper airplane in the center.. Exabeam Nova Rule Creator validates whether your description meets analytics rule field requirements, then generates a draft of the analytics rule.

  5. Review the analytics rule draft. To continue tuning the analytics rule, continue prompting Exabeam Nova Rule Creator with the changes you want to see in the analytics rule.

    You can also ask Exabeam Nova Rule Creator other questions about Threat Detection Management and analytics rules; for example, what the different analytics rule types are, or what an analytics rule field does.

  6. To save the changes, click Create Rule.

Manually Edit an Analytics Rule

Make changes to an analytics rule using the point-and-click Manual Rule Creator.

  1. For the custom analytics rule you're editing:

    • Click the More menu The more options menu; three vertical dark grey dots on an off-white background., then select Edit.

    • Right-click the analytics rule, then select Edit.

    • Select the checkbox for the analytics rule, then select Edit.

    • Select the analytics rule to view its details, then select Edit.

  2. To change the analytics rule name and type, applicable data sources, detection logic and conditions, or baseline and training, click A blue pencil overlaps the top-left corner of a blue square outline.. When you've completed all changes to these configurations, click Next.

  3. Under Rule Details, you can change other analytics rule details like rule description, contextual rule definition, rule family and group, rule template ID, and associated Exabeam use cases and MITRE ATT&CK® tactics and techniques.

  4. Click Save.

    If the analytics rule is enabled, the change is added to a batch of pending changes, and you must apply the change to your environment.