Skip to main content

Responses are generated using AI and may contain mistakes.

Threat Detection ManagementThreat Detection Management Guide

Troubleshoot Over-Triggering Analytics Rules

Fix analytics rules that are most likely to generate false positive results.

To ensure the analytics engine runs smoothly, the analytics engine monitors rule training and evaluation processes and prevents you from enabling analytics rules that are most likely to generate false positive results. Under the RULE INSIGHTS column, these analytics rules are marked as having Insights.

To troubleshoot an over-triggering analytics rule, tune the analytics rule with recommended exclusion expressions to limit the scope of events or event field values that trigger the analytics rule.

  1. To find over-triggering rules, filter for analytics rule with Insights under the RULE INSIGHTS column.

  2. For an over-triggering analytics rule, under the RULE INSIGHTS column, click Insights.

  3. If there are no suggested exclusions available, you view a message suggesting that you review the analytics rule.

    If there are suggested exclusions available, view the particular event field causing the analytics rule to over-trigger and the suggested exclusion expression that fixes the issue:

    • Under the FIELDS column, view the event fields causing the analytics rule to over-trigger.

    • Under the SUGGESTED EXCLUSIONS column, view the suggested exclusion expression that limits the event field values that trigger the analytics rule.

  4. To copy the suggested exclusion expression to your clipboard, click Two overlapping blue squares with the top square slightly offset to the left..

  5. Create an exclusion for the analytics rule and paste the suggested exclusion expression under Condition.

  6. Enable the exclusion you created for the analytics rule.