Skip to main content

Responses are generated using AI and may contain mistakes.

Threat Detection ManagementThreat Detection Management Guide

Preview Analytics Rule Details

Quickly view a summary of an analytics rule.

  1. In Threat Detection Management, navigate to the Analytics Rule tab, click the More The more menu; three vertical grey dots on a white background. menu for an analytics rule, then select Details.

  2. View information about the rule:

    The details of an analytics rule highlighted in red rectangles and callouts.
    • 1 The analytics rule type, name, and description.

    • 2 A dynamic name describing the rule and why it triggered on a specific event. It elaborates on the analytics rule name and adds detail specific to the specific event on which it triggered. It is displayed in Threat Center detections:

      The detection reason for a Threat Center analytics rule detection.

      It is defined under the detectionReason field in the analytics rule JSON configuration or under Rule Trigger Template in the analytics rule builder.

    • 3 Information about the analytics rule, including:

      • Author – Who created the analytics rule. If the analytics rule is pre-built, the author is Exabeam.

      • Severity – The analytics rule severity.

      • Created – The date and time the analytics rule was created.

      • Last update – The date and time the analytics rule was last updated.

      • Status – The state of the analytics rule:

        • Enabled – The analytics rule is enabled.

        • Disabled – The analytics rule is disabled.

        • Stopped – The analytics rule has triggered more than 50 times in five minutes and has automatically been disabled.

        • Testing – The analytics rule is being tested. It won't create Threat Center cases or alerts unless it is triggered with other analytics rules that aren't being tested. It is excluded from Threat Center case and alert risk score calculations.

        • Training – The analytics rule is in a training period and won't trigger. To view how much time is left until training is completed, hover over the status. After the analytics rule is finished training, its status is automatically changed to Enabled.

      • Last trigger – The date and time the analytics rule was last triggered.

      • Exclusions – The number of exclusions applied to the analytics rule. To view the exclusions, hover over the number. To view exclusion details, click A blue eye.

      • Rule family – The family to which the analytics rule belongs.

      • Rule group – The group to which the analytics rule belongs.

      • Required event fields – The fields an event must have for an analytics rule to trigger. This list of fields is automatically generated and used by Outcomes Navigator to calculate coverage scores.

    • 4 Exabeam use cases associated with the analytics rule.

    • 5 ATT&CK tactics and techniques associated with the analytics rule.

    • 6 The analytics rule configuration. View its key components in a human-readable format under the Summary tab. View the entire JSON configuration under the JSON tab.

  3. (Optional) Exclude, enable or disable, update, edit, export, or adjust severity of the rule: