Skip to main content

Threat Detection ManagementThreat Detection Management Guide

Enable or Disable Correlation Rules

Enable rules to activate them or disable rules to deactivate them without deleting them.

  1. In Threat Detection Management, navigate to the Correlation Rules tab, then select correlation rules to enable or disable:

    • To select all rules, click the checkbox in the header row, then click Enable or Disable.

      The actions to enable and disable all correlation rules on the page highlighted in a red rectangle.
    • To select multiple rules, click the checkbox for each rule you're enabling or disabling, then click Enable or Disable.

      The actions to enable and disable multiple correlation rules highlighted in a red rectangle.
    • Click on a single rule, then click Enable or Disable.

      The action to enable a single correlation rule highlighted in a red rectangle.
    • For a single rule, click the More menu, then select Enable or Disable.

  2. Click Enable or Disable.

    If the rule is configured to be enabled in test mode, its Enabled status is marked with a yellow triangle under the STATUS column.

    By default, only 200 sequences can be enabled at any given moment. If the rules you're enabling exceeds this limit, you receive an error and must reduce the number of rules you're enabling.