Home

> Analytics > Creating a Rule from Search

Creating a Rule from Search

With the search result displayed in Analytics, follow the steps below to create a rule:

  1. From Actions drop-down, select Create Rule.
  2. A rule template is automatically created by copying over important Search parameters:
    1. Rule Sub-pattern Filters contain Search Filter conditions.
    2. Rule Sub-pattern Group By contain Search Display conditions.
    3. Rule Aggregate Conditions are set to COUNT(Matched Events) >= 1
  3. To complete the rule, do the following:
    1. Enter the Rule Name.
    2. Enter the Description.
    3. Set the right Severity.
    4. Select the Function.
    5. Adjust the Sub-pattern definition and Action.
    6. Click OK.