The name of the rule that you specify when creating the rule. This is a mandatory field. The name appears in event details. You can use the name in queries for threat hunting.
Displays the query that is used in the rule. This is a mandatory field. You can click the Edit query button to change the search conditions. The query opens in the Threat hunting section.
Click the Create button.
An IOA rule with the searched conditions is created. You can check your IOA rules in the Custom rules section. If an IOA rule is triggered by an event, the name of the rule is displayed in the event details.