A rule is a search query that is run automatically to locate matches. A rule "hits" when its TQL query finds a match and its threshold occurs within its defined time window.
Logging without generating alerts
When a rule is set to Log Only, it executes its query and functions the same way, but it does not generate alerts. Rules set to Log Only can be used to generate assertions or reference dependencies, key components of multistage rules.
Required log sources
Note that some rules require data from specific types of log sources, and if those log sources are not present in your environment, they will not function.