CSE Rules
This guide has information about Cloud SIEM Enterprise (CSE) rules, including how to write rules, rules syntax, and CSE built-in rules.
In this section, we'll introduce the following concepts:
About CSE Rules
Learn about CSE rules, rules syntax, and how to write rules.
Before You Write a Custom Rule
Learn how to plan a custom rule and prototype rule expressions.
Match Rule
Learn how to write a match rule.
Chain Rule
Learn how to write a chain rule.
Aggregation Rule
Learn how to write an Aggregation rule.
Threshold Rule
Learn how to write a Threshold rule.
First Seen Rule
Learn about First Seen rules and how to create them in the CSE UI.
Rules Syntax
Learn about the functions you can use when writing CSE Rules.
Built-In Rules
Look at the various page lists and CSE's built-in rules.
Import YARA Rules
Learn how to import YARA rules from GitHub into CSE.
Normalized Authentication Rules
Detect activities that compromise accounts using authentication logs.
Normalized Threat Rules
Learn about CSE’s built-in normalized threat rules.
Rule Tuning
Learn how to create and use tuning expressions for rules.
Tailor a Global Rule
Learn how to tailor global (built-in) rules in CSE.