Skip to main content

Responses are generated using AI and may contain mistakes.

Threat Detection ManagementThreat Detection Management Guide

Table of Contents

Get Notified About Threat Detection Management

Get automatically notified about important Threat Detection Management activity.

You can get automatically notified about important correlation rule and analytics rule activity using platform notifications and global notifications.

Platform Notifications

Platform notifications automatically push notifications to Your Notifications whenever specific events occur. To access Your Notifications anywhere on the Exabeam Security Operations Platform, click Alert-Notification-Icon.png.

For correlation rules, you can be notified when:

  • A correlation rule is incorrectly disabled. Correlation rules are automatically disabled when the sequence uses incorrect query syntax or references an empty context table.

  • A noisy correlation rule is disabled. Correlation rules are automatically disabled when events have satisfied the conditions of a sequence more than 500 times in five minutes or when the correlation rule has triggered more than 50 times in five minutes.

For analytics rules, you can be notified when:

  • Analytics Engine Restart Completed – The analytics engine has finished restarting and has resumed detecting threats in incoming events.

  • Training Job Failed – An analytics rule has failed to complete its training period.

  • Training Job Completed – An analytics rule has completed its training period.

  • System stopped an analytics rule – The analytics rule has triggered more than 50 times in five minutes and has automatically been disabled.

To enable platform notifications for Threat Detection Management, manage your notification preferences.

Global Notifications

Global notifications automatically send messages about Threat Center to third-party applications, like Microsoft Teams or Slack, in real time whenever specific events occur.

For correlation rules, you can be notified when:

  • A correlation rule is incorrectly disabled. Correlation rules are automatically disabled when the sequence uses incorrect query syntax or references an empty context table.

  • A noisy correlation rule is disabled. Correlation rules are automatically disabled when events have satisfied the conditions of a sequence more than 500 times in five minutes or when the correlation rule has triggered more than 50 times in five minutes.

For analytics rules, you can be notified when:

  • Analytics Engine Restart Completed – The analytics engine has finished restarting and has resumed detecting threats in incoming events.

  • Training Job Failed – An analytics rule has failed to complete its training period.

  • Training Job Completed – An analytics rule has completed its training period.

  • System stopped an analytics rule – The analytics rule has triggered more than 50 times in five minutes and has automatically been disabled.

To enable global notifications for Threat Detection Management, ensure that you add your desired webhook connection, then select your notification options.