- Get Started with Threat Detection Management
- Analytics Rules
- Analytics Rule Classifications
- Create an Analytics Rule
- Manage Analytics Rules
- Tune Analytics Rules
- Find Analytics Rules
- Share Analytics Rules
- Troubleshoot Analytics Rules
- Analytics Rules Syntax
- Advanced Analytics Rule Syntax vs. Analytics Rule Syntax
- Logical Expressions in Analytics Rule Syntax'
- String Operations Using Analytics Rule Syntax
- Integer Operations Using Analytics Rule Syntax
- Time Operations Using Analytics Rule Syntax
- Network Operations Using Analytics Rule Syntax
- Context Operations Using Analytics Rule Syntax
- Entity Operations Using Analytics Rule Syntax
- Correlation Rule Operations Using Analytics Rule Syntax
- Analytics Engine Status
- Correlation Rules
- Threat Scoring
Test Analytics Rules
Test analytics rules and ensure they work as expected. Analytics rules you're testing do not create Threat Center cases or alerts unless they're triggered with other analytics rules that aren't being tested.
Analytics rules you're testing are also not used to calculate Threat Center case and alert risk scores when triggered.
Its severity is automatically changed to None.
In the Analytics Rules tab, select the analytics rules you're testing:
To select a single analytics rule, select the rule to view its details, click the More menu
, right-click the analytics rule, or select the checkbox for the analytics rule, then select Testing.To select specific analytics rules, select the checkbox for each rule, then select Testing.

To select all analytic rules in the list, click the checkbox in the header row, then select Testing.

If the analytics rule is enabled, you receive a warning that the analytics rule severity is automatically changed to None. Click Change. The change is added to a batch of pending updates.
If the analytics rule is disabled, the change is automatically added to a batch of pending updates.
Apply the change to your environment.
After you're done testing the analytics rule, you can remove it from testing by enabling or disabling it.