ESET Online Help

Search English
Select the topic

Sequence rules

Sequence rules

Sequence rules enable you to create incidents when detections occur in a specific sequence.

Example:

Things to notice in the rule example above:

1.The sequence tag specifies how many times the entire sequence has to match for the incident to be created and the maximum time between the first detection and the last detection in the sequence.

2.In the example above, for the sequence rule to trigger, Rule 01 and Rule 02 have to trigger a detection in that order twice in the span of 1 minute.

3.The aggregateOn tag specifies the conditions for which rule triggers should be grouped together.
       Possible values are:

oComputer

oProcess

oParentProcess

4.The only available action is ReportIncident.