Create Detection Rule from Logs
Administrator5 min
What it's for
Turn an investigation query into a permanent detection rule.
Steps
- In Table View, use the Create Detection Rule icon (shield), or context menu → `Create Detection Rule`.
- Opens `/management/detection-rules?create=true` with the query preloaded.
- Complete the rules wizard (Detection Rules).
Expected result
- Rules wizard open with SQL query preloaded.