Running a rule against live data

When you create a rule, it does not initially search for detections based on events received in your Chronicle account in real time. However, you set the rule to search for detections in real time by setting the Live Rule toggle to enabled.

To set a rule to live, complete the following steps:

  1. Navigate to the Rules Dashboard.

  2. Click the Rules option icon for a rule and toggle the Live Rule to enabled.

    Live rule

    Live Rule

  3. You can view detections generated by a live rule by choosing View Rule Detections.