- Get Started with Threat Detection Management
- Analytics Rules
- Analytics Rule Classifications
- Create an Analytics Rule
- Manage Analytics Rules
- Tune Analytics Rules
- Find Analytics Rules
- Share Analytics Rules
- Troubleshoot Analytics Rules
- Analytics Rules Syntax
- Advanced Analytics Rule Syntax vs. Analytics Rule Syntax
- Logical Expressions in Analytics Rule Syntax'
- String Operations Using Analytics Rule Syntax
- Integer Operations Using Analytics Rule Syntax
- Time Operations Using Analytics Rule Syntax
- Network Operations Using Analytics Rule Syntax
- Context Operations Using Analytics Rule Syntax
- Entity Operations Using Analytics Rule Syntax
- Correlation Rule Operations Using Analytics Rule Syntax
- Analytics Engine Status
- Correlation Rules
- Correlation Rule Sequences
- Correlation Rules Templates
- Create Correlation Rules
- Create a Correlation Rule Using the Exabeam Nova Rule Creator
- Create a Correlation Rule from Scratch Using the Manual Rule Creator
- Create a Correlation Rule from a Template
- Create a Correlation Rule from Search
- Group by Field in Correlation Rules
- Detect Absent Events or Fields Using Correlation Rules
- Granular Suppression
- Correlation Rule Evaluation Delay
- Manage Correlation Rules
- Find Correlation Rules
- Share Correlation Rules
- View Correlation Rules Metrics
- Threat Scoring
- Get Notified About Threat Detection Management
Get Notified About Threat Detection Management
Get automatically notified about important Threat Detection Management activity.
You can get automatically notified about important correlation rule and analytics rule activity using platform notifications and global notifications.
Platform Notifications
Platform notifications automatically push notifications to Your Notifications whenever specific events occur. To access Your Notifications anywhere on the Exabeam Security Operations Platform, click
.
For correlation rules, you can be notified when:
A correlation rule is incorrectly disabled. Correlation rules are automatically disabled when the sequence uses incorrect query syntax or references an empty context table.
A noisy correlation rule is disabled. Correlation rules are automatically disabled when events have satisfied the conditions of a sequence more than 500 times in five minutes or when the correlation rule has triggered more than 50 times in five minutes.
For analytics rules, you can be notified when:
Analytics Engine Restart Completed – The analytics engine has finished restarting and has resumed detecting threats in incoming events.
Training Job Failed – An analytics rule has failed to complete its training period.
Training Job Completed – An analytics rule has completed its training period.
System stopped an analytics rule – The analytics rule has triggered more than 50 times in five minutes and has automatically been disabled.
To enable platform notifications for Threat Detection Management, manage your notification preferences.
Global Notifications
Global notifications automatically send messages about Threat Center to third-party applications, like Microsoft Teams or Slack, in real time whenever specific events occur.
For correlation rules, you can be notified when:
A correlation rule is incorrectly disabled. Correlation rules are automatically disabled when the sequence uses incorrect query syntax or references an empty context table.
A noisy correlation rule is disabled. Correlation rules are automatically disabled when events have satisfied the conditions of a sequence more than 500 times in five minutes or when the correlation rule has triggered more than 50 times in five minutes.
For analytics rules, you can be notified when:
Analytics Engine Restart Completed – The analytics engine has finished restarting and has resumed detecting threats in incoming events.
Training Job Failed – An analytics rule has failed to complete its training period.
Training Job Completed – An analytics rule has completed its training period.
System stopped an analytics rule – The analytics rule has triggered more than 50 times in five minutes and has automatically been disabled.
To enable global notifications for Threat Detection Management, ensure that you add your desired webhook connection, then select your notification options.