How rules generate alerts

Prev Next

A rule is a search query that is run automatically to locate matches. A rule "hits" when its TQL query finds a match and its threshold occurs within its defined time window.

Logging without generating alerts

When a rule is set to Log Only, it executes its query and functions the same way, but it does not generate alerts. Rules set to Log Only can be used to generate assertions or reference dependencies, key components of multistage rules.

    Required log sources

    Note that some rules require data from specific types of log sources, and if those log sources are not present in your environment, they will not function.