Skip to main content

Threat Detection ManagementThreat Detection Management Guide

Import Analytics Rules

Import analytics rules you created into an environment.

  1. On the Analytics Rules tab, click Import analytics rules A partial rounded blue square from which emerges an arrow curving downwards and to the left, both of which are set inside a blue square..

  2. Click Select File, then select a JSON file containing no more than 50 rules and is no larger than 4 MB.

    Threat Detection Management validates the analytics rules in the file to ensure you're not importing duplicate analytics rules that already exist in your environment and there are no syntax errors in the analytics rules. Analytics rules that are successfully validated have a green check mark. Troubleshoot any warnings or errors you encounter.

  3. After the analytics rules are validated, click Import Rules.

    Imported analytics rules are automatically disabled. The analytics rule author is the account that imported the rule. The analytics rule Created time is the date and time the rule was imported.

    After you import the analytics rules, you can further tune them using exclusions. To activate the analytics rules and allow them to trigger in your environment, you must enable them.