Overview
Presets are templates for customizing parameters of content deployed to your organization's SIEM on the fly. This helps streamline content management operations and avoid errors that can occur when manually editing content. A Preset can be applied:
On a Detection Rule page before individual content item deployment
In a Job as part of automated deployment
In Prime Architect when translating a Sigma rule
You can create Presets for the following platforms:
Coralogix
CrowdStrike Next-Gen SIEM
Microsoft Sentinel
Microsoft Sentinel (YAML)
Elastic (Detection Rule (ES|QL))
Sumo Logic
Humio
Elastic
Google SecOps
Splunk
The Presets page lists all Presets available to you:
My – Presets created by you
Company – Presets created by your team and shared across your organization
All Presets are displayed as a table with the following columns:
Column Name | Description |
Preset Name | The name defined during configuration |
Platform | Platform associated with the Preset |
Shared | Indicates whether the Preset is shared across your organization |
Created by | The user who created the Preset |
Last Updated By | The user who made the last update to the Preset |
Created | The date of the Preset creation |
Updated | The date of the last update to the Preset |
You can look for an existing Preset using the Search bar.
Create Preset
You can create Presets from the Presets page or from the Detection Rule page.
Open the Create New Preset Profile modal using one of the following methods:
Option A: From the Presets page
Option B: From the Detection Rule page
Go to the Search page and select a rule from the list.
On the Detection Code tab of a Detection Rule page, open the Preset dropdown and select the Create New Preset option.
Once created, you can select this Preset from the dropdown list, and the detection content for the associated platform will be updated depending on the applied preset.
Provide the Preset name and turn on the Share to Company toggle if you'd like to make this Preset available for viewing and editing to all users from your company.
Select the platform.
Fill in all the required fields. The available fields differ depending on the selected platform and may include options such as Query Period, Severity ("Low", "Medium", "High", "Critical"), Rule Status ("Enabled", "Disabled"), etc. For more information about each field, hover over its tooltip.
Optionally, you can link filters by selecting them in the dropdown of the Filters field. To learn how to create Filters, follow this guide.
Click the Create Profile button, and the created Preset will appear on the Presets page.
After creating a new Preset, link it to a Job before running this Job for customizing automated content deployment.
Edit or Delete a Preset
On the Presets page, you can edit or delete all Presets created by you.
Note: If a Preset is deleted, all active Jobs linked to it will be disabled. |
To perform one of these actions:

