Custom detection rules allow you to create rules to detect events specific to your needs.
To create a custom detection rule:
On the Rules page, select Create New Rule.
Enter a name and optional description, and select a severity from the menu.
Write the rule condition. To ensure the rule will work, Helix validates the syntax as you type. It looks for errors in the YAML schema, validates datatypes, some regular expressions, for example
within: 3h. It also validates the fields, correlation, cardinality, and deviation conditions. If there is an error, hover over the colored icon for more information. You cannot save a rule until all errors are fixed.Note
Validation is not available for the match expression.
(Optional) Add tags and select an exclusion list.
Click Save.
The following table gives more information on each field of the custom detection rule.
Field | Description |
|---|---|
Tenant ID | If you are a federated customer, select the tenant from the menu. |
Name | Enter a name for the rule that briefly describes what it does. The name should be descriptive enough to find by scanning the Rules table. |
Description | Provide a more detailed description of the rule, if desired. |
Severity | Select a severity that matches the impact an alert triggered by this rule would have on your organization. |
Condition | Enter the rule conditions. For more information, see Understanding the rule language. |
Status | Enabled, Disabled, or Muted. Rules are enabled by default. Mute the rule to evaluate its performance over time, without showing alerts by default in the alert table. |
Exclude these lists | A file containing a list of fields to exclude from the rule. |
Tags | Select any tags that can categorize the rule. |