Providing Conditions for Event Rarity
The Event Rarity algorithm identifies an entity's normal behavior based on the features selected and compares it with past behavior to detect the first time that a new type of transaction occurs. This policy learns from the repeated rare behavior of the user to distinguish new behavior from truly rare behavior. You can create the policy to run on datasources or for a functionality, and configure the number of days to observe the behavior to establish whether it is truly rare (i.e. it doesn't happen again within that number of days) or to determine the behavior was new for the entity and will be whitelisted (i.e. the behavior happens again within the number of days). Only behavior that is truly rare will be flagged as a violation. For What do you Want to Detect, choose Event Rarity. For Choose the Features for Generating Behavior, based on the policy, select the attributes Unified Defense SIEM will use to learn normal behavior. Behavior profiles are generated on a combination of the sel
, function (e) { // Prevent Chrome 76 and later from showing the mini-infobar e.preventDefault(); // Stash the event so it can be triggered later. window[
Explore this link on the map →related reading
- Securonix Documentationdocumentation.securonix.com
- Securonix Documentationdocumentation.securonix.com
- GitHub - open-edge-platform/anomalib: An anomaly detection library comprising state-of-the-art algorithms and features such as experiment management, hyper-parameter optimization, and edge inference. · GitHubgithub.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- Securonix Documentationdocumentation.securonix.com
- Security incident disclosure — July 2026huggingface.co
- Dealing with Noisy Behavioral Analytics in Detection Engineering | CMU Software Engineering Instituteinsights.sei.cmu.edu
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- GitHub - salesforce/AuditNLG: AuditNLG: Auditing Generative AI Language Modeling for Trustworthiness · GitHubgithub.com
- Securonix Documentationdocumentation.securonix.com
- Securonix Documentationdocumentation.securonix.com