Configure Detection Event Rule

You can establish rules for detecting events that trigger ticket creation based on Posture, Criticality, Status, Policy ID, Host, and Control.

You can create two types of detection event rules:

  • One-to-One Rules: The one-to-one Rules create a separate posture incident for each posture. You must set the one-to-one detection event rules to create grouping rules.
  • Grouping Rules: The Grouping Rules use the posture incidents created by the one-to-one rules and group the incidents based on different criteria.