Note: there's no visible "New Rule" button in the current UI — only editing, enabling/disabling, and deleting an existing rule. The create path exists in the underlying code but nothing in the interface reaches it. Don't look for a way to add a new rule from scratch; confirm this is still true when you review.
Adjust the threshold, response, and notification behavior of an existing automated detection rule.
Before you start
The Manage Detection Rules right (separate from, and in addition to, the Manage Access Rules right needed for the rest of the Security section — without it, you're locked to the read-only Logs sub-view even if you try to reach Detection Rules directly).
Steps
- Go to Settings → System Security → System Access Logs, then switch to the Detection Rules Configuration sub-tab.
- Each rule shows its type, a summary of its threshold/window/actions, an Active/Disabled chip, and an enable/disable switch.
- Toggle the switch to turn a rule on or off directly from the list.
- Click the Edit (pencil) icon to open Edit Detection Rule: {rule type} and adjust:
- Enabled switch
- Threshold Count and Window (minutes) — how many matching events in what time window trigger the rule
- Business Hours Start/End and Business Hours Timezone (free text, e.g. "America/New_York")
- Response Actions — checkboxes: Log Only, Auto-Block IP (Temporary), Lock Account, Force Logout, Notify Admin (Email)
- Temp Block Duration (minutes) — used if Auto-Block IP is checked
- Notification Emails — comma-separated, used if Notify Admin is checked
- Save.
To remove a rule
Click the Delete (trash) icon on the rule's row.
What you'll see
Changes apply to future matching events immediately. A triggered rule's actions (auto-block, force logout, etc.) show up as their own event types in System Access Logs, so you can confirm a rule is actually firing.
Related articles
Other guides that answer questions close to this one.
Detection Rules Explained
A detection rule watches for a pattern of events — a Threshold Count of matching events within a Window of minutes — and automatically fires one or more Response Actions when that pattern is hit: log it only,…
How to Manage Access Blocks and Geo-Blocking
Control which IPs and countries can reach your organization — four related lists on one screen. Before you start The Manage Access Rules right. Steps Go to Settings → System Security → Access Blocks. There are four…
How to Review System Access Logs
Note: the Settings landing page card for this used to be called "Suspicious Behavior" — that name and its old URL slug (?tab=suspicious-behavior) are stale leftovers from a rename; the real, current tab is "System…