Documentation forSecurity Event Manager

The Rules view on the SEM Console

To open the Rules view on the SEM Console, navigate to Build > Rules on the SEM menu bar. Use this view to create and manage rules, rule categories, and rule templates. This topic describes the Rules grid and the sidebar.

Below is an example of the Rules view.

The Rules grid

The Rules grid contains all policy rules configured for all Managers connected to the console. The Manager column indicates which Manager each rule applies to.

By default, this view displays the rules from the Custom Rules folder in the Folders pane. If you do not have any custom rules, click the Rules folder to list the rules included with the console.

The following table describes each column in the Rules grid.

Column Description

Opens a drop-down with a list of commands you can perform on selected grid item.


Indicates the rule availability for use with your policies.

indicates an enabled and active rule.

indicates a disabled and inactive rule.


Indicates the rule test mode status.

When a rule is in test mode, the event appears in the console. but it cannot perform any active responses. This lets you see how the rule would behave when it is fully enabled, but without risking any negative unintended consequences.

indicates the rule is in test mode.

indicates the rule is not in test mode.

You can only test an enabled rule.


The rule name.


The rule description. Pointing to this field displays the complete description as a tooltip.


The folder name (in the Folders pane) where the rule is stored.

Created By

The console user who created the rule.

Created Date

The date the rule was created.

Modified By

The console user who last modified the rule.

Modified Date

The date and time the rule was last modified.


The Manager associated to the rule.

The Refine Results form

Use the Refine Results form to search for rules and rule templates. The form returns matching results in the Rules grid. The remaining grid items are available, but hidden. To restore the hidden items, click Reset or select All in the refinement lists you are using.

The following table describes the fields that make up the Refine Results form in the Rules sidebar.

Field Description


Click Reset to clear the form. This returns the form and the Rules grid to their default settings.


Use this Search field to perform keyword searches for specific rules. To search, type the text you want to search for in the text box. The grid displays only those rules whose Name fields match or include the text you entered.


Select this check box to display Enabled rules only. Clear this check box to display both Enabled and Disabled rules.


Select this check box to display rules that are in test mode. Clear this check box to display rules that are in and out of test mode.


Select a Manager to display all rules associated with the Manager.

Created By

Select the console user who created the rule and display only rules created by that user.

Created Date Range

Type or select a date range to display rules created within that date range.

Modified By

Select the console user who last modified and display only rules modified by that user.

Modified Date Range

Type or select the date range to display rules that were modified on or within that date range.

The Rule Categories & Tags pane in the Rules sidebar

Click a category to expand it and view the rules and rule templates filtered by the highlighted tag.