Creating IOA rules from queries

March 20, 2024

ID 221532

Expand all | Collapse all

You can create IOA rules based on the built queries.

To create an IOA rule:

  1. In the main menu, go to MONITORING & REPORTING THREAT HUNTING.
  2. Enter a query in the query search box.
  3. Click the Create IOA rule button under the search box.

    The New rule window opens.

  4. Specify the following details:
    • Name
    • State
    • Severity
    • Confidence
    • Action
    • Description
    • Recommendations
    • Possible false positives
    • Query
  5. Click the Create button.

An IOA rule with the searched conditions is created. You can check your IOA rules in the Custom rules section. If an IOA rule is triggered by an event, the name of the rule is displayed in the event details.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.