Skip to main content

Presets

Customizing content settings before deployment with Presets | Setting up and managing Presets

S
Written by Sergey Bayrachny

Overview


Presets are templates for customizing parameters of content deployed to your organization's SIEM on the fly. This helps streamline content management operations and avoid errors that can occur when manually editing content. A Preset can be applied:

You can create Presets for the following platforms:

  • Coralogix

  • CrowdStrike Next-Gen SIEM

  • Microsoft Sentinel

  • Microsoft Sentinel (YAML)

  • Elastic (Detection Rule (ES|QL))

  • Sumo Logic

  • Humio

  • Elastic

  • Google SecOps

  • Splunk

The Presets page lists all Presets available to you:

  • My – Presets created by you

  • Company – Presets created by your team and shared across your organization

All Presets are displayed as a table with the following columns:

Column Name

Description

Preset Name

The name defined during configuration

Platform

Platform associated with the Preset

Shared

Indicates whether the Preset is shared across your organization

Created by

The user who created the Preset

Last Updated By

The user who made the last update to the Preset

Created

The date of the Preset creation

Updated

The date of the last update to the Preset

You can look for an existing Preset using the Search bar.

Create Preset


You can create Presets from the Presets page or from the Detection Rule page.

  1. Open the Create New Preset Profile modal using one of the following methods:

    Option A: From the Presets page

    1. Select the Account icon > Platform Settings > Presets.

    2. Click the Add Preset button.

    Option B: From the Detection Rule page

    1. Go to the Search page and select a rule from the list.

    2. On the Detection Code tab of a Detection Rule page, open the Preset dropdown and select the Create New Preset option.

      Once created, you can select this Preset from the dropdown list, and the detection content for the associated platform will be updated depending on the applied preset.

  2. Provide the Preset name and turn on the Share to Company toggle if you'd like to make this Preset available for viewing and editing to all users from your company.

  3. Select the platform.

  4. Fill in all the required fields. The available fields differ depending on the selected platform and may include options such as Query Period, Severity ("Low", "Medium", "High", "Critical"), Rule Status ("Enabled", "Disabled"), etc. For more information about each field, hover over its tooltip.

  5. Optionally, you can link filters by selecting them in the dropdown of the Filters field. To learn how to create Filters, follow this guide.

  6. Click the Create Profile button, and the created Preset will appear on the Presets page.

After creating a new Preset, link it to a Job before running this Job for customizing automated content deployment.

Edit or Delete a Preset


On the Presets page, you can edit or delete all Presets created by you.

Note:

If a Preset is deleted, all active Jobs linked to it will be disabled.

To perform one of these actions:

  1. Go to the Account > Platform Settings > Presets.

  2. Click the three dots on the right and select Edit or Delete.

  3. Edit the fields in the modal and save changes, or confirm the deletion.

Did this answer your question?