Rules guide

A rule is defined using XML-based language.

Rules are matched on the server. They are matched asynchronously, so there can be a small delay between when recent events are sent from the client to the server and processed by rules. A matched rule triggers associated actions and notifies a security engineer by raising a detection. The detection is displayed in the Detections view. It is also exported to ESET PROTECT (or SIEM), or an email can be automatically sent when the detection is triggered.