Skip to main content

Threat Detection ManagementThreat Detection Management Guide

Enable Analytics Rules

Enable analytics rules to activate them and allow them to trigger in your environment.

You can enable an individual analytics rule or multiple analytics rules at once.

You can enable only a limited number of analytics rules. To review the maximum number of analytics rules you're allowed to enable, under the Threat Detection Management Analytics Rules tab, navigate to the Limit chart:

The Limit chart under the Analytics Rules tab.

Under Exabeam Rules, view the number of pre-built analytics rules enabled compared to the maximum your entitlement allows. Under Custom Rules, view the number of custom analytics rules enabled compared to the maximum your entitlement allows.

Enable an Analytics Rule

  1. For the analytics rule you're enabling, click the More menu The more options menu; three vertical dark grey dots on an off-white background. or right-click the analytics rule, then select Enable. The change is added to a batch of pending updates. You must now apply the change to your environment for the change to take effect.

  2. Under Engine Status, click View Changes.

    The Engine Status showing pending analytics rule changes waiting to be processed.
  3. Review all rules with pending changes:

    • Name – The name of the rule with pending changes.

    • Update – The nature of the change. Update indicates that the change modifies the rule. Obsolete indicates that the change removes the rule.

    • Change – The nature of the change. Updating indicates that the change modifies the rule. Deleting indicates that the change deletes the rule.

    • Actions – View rule details or delete the change. To view rule details, click A blue eye.. To delete the change, click A blue trash can..

    To find specific rules, filter the rules by Update or Change columns.

  4. Ensure you select the checkbox for the analytics rule you enabled. You can also select other analytics rule changes you want to apply to your environment.

  5. Determine whether the analytics engine re-trains on past events using the rule changes:

    • To apply rule changes without re-training the analytics engine on past events, select Apply Changes Without Training.

      Consider applying changes without training if you want to apply the changes immediately, minimize disruptions to other Exabeam applications, ensure the analytics engine continues to run in real time, and ensure you don't use any of your entitled training days.

      Keep in mind that applying changes without training increases the risk of false positives and limits the analytics engine from adapting to evolving patterns in entity behavior.

    • To re-train the analytics engine on past events with the rule changes, select Apply Changes and Re-train. By default, the analytics engine begins training using the rule changes on the past 21 days of event data. After the analytics engine finishes training, analytics rules continue to trigger on incoming events in real-time.

      To change the start date of events the analytics engine uses to re-train:

      1. Click Advanced Settings.

      2. Under Training Start Date, click the date field, then select a date using the calendar. You can re-train the analytics engine on up to 30 days of events, with a recommended minimum of 14 days of events.

      3. Click Confirm.

  6. Click Apply Rule Changes. If you selected Apply Changes and Re-train or Trigger on Historical Events, the analytics engine temporarily stops processing incoming events to re-train on past events using the rule changes.

Enable Multiple Analytics Rules

  1. Select the analytics rules you're enabling:

    • To select all analytics rules, click the checkbox in the header row.

      All listed analytics rule selected.
    • To select specific analytics rules, click the checkbox for each analytics rule.

      Three analytics rules selected.
  2. Click Enable:

    The enable action when you select multiple analytics rules highlighted in a red rectangle.

    The change is added to a batch of pending updates. You must now apply the change to your environment for the change to take effect.

  3. Under Engine Status, click View Changes.

    The Engine Status showing pending analytics rule changes waiting to be processed.
  4. Review all rules with pending changes:

    • Name – The name of the rule with pending changes.

    • Update – The nature of the change. Update indicates that the change modifies the rule. Obsolete indicates that the change removes the rule.

    • Change – The nature of the change. Updating indicates that the change modifies the rule. Deleting indicates that the change deletes the rule.

    • Actions – View rule details or delete the change. To view rule details, click A blue eye.. To delete the change, click A blue trash can..

    To find specific rules, filter the rules by Update or Change columns.

  5. Ensure you select the checkbox for the analytics rules you enabled. You can also select other analytics rule changes you want to apply to your environment.

  6. Determine whether the analytics engine re-trains on past events using the rule changes:

    • To apply rule changes without re-training the analytics engine on past events, select Apply Changes Without Training.

      Consider applying changes without training if you want to apply the changes immediately, minimize disruptions to other Exabeam applications, ensure the analytics engine continues to run in real time, and ensure you don't use any of your entitled training days.

      Keep in mind that applying changes without training increases the risk of false positives and limits the analytics engine from adapting to evolving patterns in entity behavior.

    • To re-train the analytics engine on past events with the rule changes, select Apply Changes and Re-train. By default, the analytics engine begins training using the rule changes on the past 21 days of event data. After the analytics engine finishes training, analytics rules continue to trigger on incoming events in real-time.

      To change the start date of events the analytics engine uses to re-train:

      1. Click Advanced Settings.

      2. Under Training Start Date, click the date field, then select a date using the calendar. You can re-train the analytics engine on up to 30 days of events, with a recommended minimum of 14 days of events.

      3. Click Confirm.

    • To re-train the analytics engine and ensure analytics rules trigger on past events, select Trigger on Historical Events, then:

      1. Under Triggering Start Date, specify the the start date of events the analytics engine uses to trigger analytics rules. Click the date field, select a date using the calendar.

      2. Under Advanced Settings, change the start date of events the analytics engine uses to re-train. Under Training Start Date, click the date field, then select a date using the calendar. You can re-train the analytics engine on up to 30 days of events, with a recommended minimum of 14 days of events. Click Confirm.

      3. Having analytics rules trigger on past events may make some Threat Center detections and their associated cases or alerts obsolete. To allow obsolete cases or alerts to be automatically deleted, select Allow changes to closed cases.

      4. You must select the disclaimer, By enabling this option, you acknowledge that reprocessing may disrupt connections with other system components (e.g., alerts, cases, timelines). Some features may be temporarily unavailable during reprocessing.

  7. Click Apply Rule Changes. If you selected Apply Changes and Re-train or Trigger on Historical Events, the analytics engine temporarily stops processing incoming events to re-train on past events using the rule changes.