Create entity rules#

Note

Required fields are marked with an asterisk (*).

A rule must be Enabled for it to take effect. See Manage entity rules.

Start creating a rule:

  1. From the left sidebar, select Data configuration icon Data configuration > Rules > Entity.

  2. Select +.

OR

  • From the left sidebar, select + Create > Rules Rules > Entity rule

Configure the rule#

In the Create entity rule view, fill out the following fields:

Rule name*

Name of rule.

Description

Short description. Should contain context and information on what this rule does.

Run on new data#

Under Run on new data, select Enable rule execution for new entities to control whether the rule automatically runs against new entities. When selected, the rule executes automatically each time an entity is ingested or created.

When left unselected, the rule does not run on new data. This is useful when you want to apply a rule only retroactively to existing entities - without affecting future ingests. You can trigger a retroactive run from the rule’s details page; see Manage entity rules.

Set criteria#

Set the Criteria selection section, select at least one or more criteria that this rule will match.

Your rule runs only if an entity meets all the criteria set here.

  • Select + Add Criteria to add a criterion to the rule.

  • Select the x to the right of an existing criterion to remove it from the rule.

The following is a table of available criteria:

Criteria

Description

Entity types

Select one or more entity types that this rule runs against.

Keyword criteria

Match entities by terms in their Title, Description, or Tags. Supports inline keywords and references to keyword lists. See Keyword criteria

Content criteria

See Content criteria tool

Sources

Select one or more sources. This rule runs against entities that belong to these sources.

TLPs

Select one or more TLPs. This rule runs against entities that have at least one of these TLPs assigned.

Set actions#

Set the Actions section, select at one or more actions that the rule performs when it matches an entity.

  • Select + Action to add an action to the rule.

  • Select the x to the right of an existing action to remove it from the rule.

For available actions, see Entity rule actions.