Skip to main content

CSE Rules

This guide has information about Cloud SIEM Enterprise (CSE) rules, including how to write rules, rules syntax, and CSE built-in rules.

In this section, we'll introduce the following concepts:

icon

About CSE Rules

Learn about CSE rules, rules syntax, and how to write rules.

icon

Before You Write a Custom Rule

Learn how to plan a custom rule and prototype rule expressions.

icon

Match Rule

Learn how to write a match rule.

icon

Chain Rule

Learn how to write a chain rule.

icon

Aggregation Rule

Learn how to write an Aggregation rule.

icon

Threshold Rule

Learn how to write a Threshold rule.

icon

First Seen Rule

Learn about First Seen rules and how to create them in the CSE UI.

icon

Rules Syntax

Learn about the functions you can use when writing CSE Rules.

icon

Built-In Rules

Look at the various page lists and CSE's built-in rules.

icon

Import YARA Rules

Learn how to import YARA rules from GitHub into CSE.

icon

Normalized Authentication Rules

Detect activities that compromise accounts using authentication logs.

icon

Normalized Threat Rules

Learn about CSE’s built-in normalized threat rules.

icon

Rule Tuning

Learn how to create and use tuning expressions for rules.

icon

Tailor a Global Rule

Learn how to tailor global (built-in) rules in CSE.

Legal
Privacy Statement
Terms of Use

Copyright © 2023 by Sumo Logic, Inc.