Solutions and Applications
...
AI SOC Applications
Signal Routing Rules (RULE)
signal routing rules control how signals are routed to playbooks each rule is a record (for example, rule 29) that you can open, edit, and enable routing rule management dashboard the primary place to manage routing rules is the routing rule management dashboard the dashboard shows all rules in a table ordered by rule order (ascending) rule order is unique and evaluated like firewall rules the first matching rule runs, so order matters from the dashboard you can reorder rules use the drag handles (stack of dots) in the order column to drag and drop rules into the desired order reordering changes which rule runs first when multiple rules could match open the rule record click the id column icon (open in new view) or the edit (pencil) icon to open the rule record and change conditions, playbook, or description open the associated playbook click the associated playbook link to open the playbook that runs when the rule matches enable or disable a rule use the enabled toggle for each row rules are inactive when disabled; only enabled rules evaluate and trigger playbooks edit a rule click the edit (pencil) icon to open the rule record in a slider or view so you can modify conditions, rule application , selected playbook , or other fields delete a rule use the delete (trash) icon to remove a rule use with care; deletion cannot be undone from the ui use add new rule on the dashboard to create a rule, or apply to save order changes after reordering 1\) open signal routing rules navigate to application records > signal routing rules or open the routing rule management dashboard to view and manage all rules open an existing rule via the dashboard edit icon or by opening it from the application list 2\) core fields rule identity rule name, description, rule order , rule uuid logic conditions, target, rule application execution selected playbook , status , records matched audit created by, last updated by, first created, last updated, history 2a) tabs rule define conditions and rule application, and associate a playbook history review routing rule changes over time support run the rule manually against pending signals and view records matched 2a) rule validation use records matched to confirm rule behavior rule order is unique per rule; keep order intentional so the first match wins admin tips manage rules from the routing rule management dashboard for a clear view of order and status keep rule order intentional so the first matching rule fires as expected use records matched to validate expected behavior commonly used fields rule name, description, rule order to identify the rule conditions and rule application to define matching logic selected playbook and status to control execution records matched to verify effectiveness select ai soc playbook available directly in the routing rule record view lets you associate a routing rule with a playbook so the playbook triggers when the rule emits events only single flow playbooks with an flow event trigger appear in the dropdown detailed workflow start with conditions that target a specific signal type or source set rule order so higher priority rules evaluate first choose a selected playbook and enable the rule monitor records matched and adjust conditions as needed