[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-04 (世界標準時間)。"],[[["\u003cp\u003eArchiving a rule hides its security data without deletion, and limits available functionality compared to active rules.\u003c/p\u003e\n"],["\u003cp\u003eArchived rules are not displayed on the Rules Dashboard, but the Test Rule function can still be used.\u003c/p\u003e\n"],["\u003cp\u003eTo view rules, navigate to Detection > Rules & Detections, select the Rules Editor tab, and filter by Show All, Active Rules, or Archived Rules.\u003c/p\u003e\n"],["\u003cp\u003eA rule can be archived by selecting the Archive Rule option within a specific rule's menu, and this action automatically disables alerting and is not allowed if the live toggle is on, or if there are retrohunts in progress.\u003c/p\u003e\n"],["\u003cp\u003eUnarchiving a rule can be done by selecting the Unarchive option in a rule's menu.\u003c/p\u003e\n"]]],[],null,["# Archive rules\n=============\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nArchiving a rule enables you to hide the security data related to that rule (and all of its versions) without actually deleting the rule. Much of the functionality available for active rules (for example, enabling a rule) is not available for archived rules.\n\nNote the following:\n\n- Rules Dashboard does not display archived rules.\n- Test Rule can be used on archived rules.\n\nViewing rules\n-------------\n\nComplete the following steps to navigate to the **View Rules** page:\n\n1. In the navigation bar, click **Detection \\\u003e Rules \\& Detections**.\n2. Select the **Rules Editor** tab to view the rules page.\n3. Click the filter icon at the top-right corner of the left navigation tab. The menu provides the following options: **Show All** , **Active Rules** , and **Archived Rules**.\n\nViewing rule detections\n-----------------------\n\nOn the **Rules Editor** tab, select **View Rule Detections** from the drop-down\nlist available on the top-right corner. The **Rule Detections** page appears.\n\nArchiving a rule\n----------------\n\nTo archive a rule, complete the following steps:\n\n1. Select a rule in the left navigation and click the option icon in the top-\n right corner of the Google Security Operations user interface. Select **Archive Rule** from the\n menu.\n\n Note the following:\n - Archiving is allowed even if the Alerting toggle is ON, it is automatically disabled.\n - Archiving is NOT allowed unless the Live toggle is disabled.\n - Archiving is NOT allowed unless there are NO Retrohunts in progress.\n2. The following window is displayed with a message confirmation.\n\n\n **Confirm Archive message**\n\n\n **Confirm Archive message continued**\n\nUnarchiving a rule\n------------------\n\nTo unarchive a rule, complete the following steps:\n\n1. Click the option icon for a specific rule in the left navigation pane. A menu\n appears with the following options: **View Detections** , **Duplicate** , and **Unarchive**.\n\n2. Select **Unarchive**.\n\n3. Select a rule in the left navigation pane and click the option icon in the\n top right corner of the Google SecOps user interface. A menu appears with\n the following options: **View Detections** , **Duplicate** , and **Unarchive**.\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]