Severity Rules
12 min
event severity is a classification that helps you evaluate and respond to exposures and threats it gives you a quick assessment on how serious a given event is, based on contextual sensitivity and threat indicators each event in your tenant is assigned one of five severity levels, ranked from \<font color="#2166ae">`info`\</font> to \<font color="#be185d">`critical`\</font> , using a framework developed by flare to provide a standardized risk indicator across all teams monitoring threats severity rules are the building blocks behind the severity assigned to an event each rule pairs a saved query with a severity, and when an event matches a rule, the rule is applied and contributes to the event's final severity there are two types of severity rules \<font color="#4338ca">\</font> added and maintained centrally by flare these rules provide coverage out of the box, so every organization can benefit from them flare rules cannot be edited, but they can be turned on or off, and the severity level can be changed \<font color="#4338ca">\</font> created in your tenant and maintained by your organization to cover your context for example, flagging events that mention a specific internal codename these rules apply only in the tenant where they were created important to note changes to a flare or custom severity rule are not applied retroactively creating or modifying a rule affects only the events that arrive after the change the severity already assigned to past events is not recalculated to reflect the new rule flare severity rules these rules are available on all tenants and are maintained centrally by flare while these rules can't be edited, they can be turned on/off, and the severity level can be changed follow these steps to view and manage the flare severity rules navigate to the identifiers page from the navigation menu on the left click on the severity rules tab flare rules are labeled flare in the type column click on a rule to view its details you can make the following changes to a flare severity rule change the severity level by selecting the required value activate or deactivate the rule using the active toggle click save to apply your changes changing a flare rule you can diverge from a flare rule's default behavior by changing the default severity of a flare rule disabling the flare rule and creating a custom rule in its place any changes apply to your tenant only, without affecting the rules for any other tenant to restore the flare default, activate the disabled flare rule and remove the custom rule, with no lasting side effects on future events events that were assigned a severity before the change are not re evaluated custom severity rules custom severity rules can be created for each individual tenant and determine the severity for the events in that tenant only follow these steps to create a custom severity rule navigate to the identifiers page from the navigation menu on the left select the severity rules tab, then select create rule enter a name and description, then add a query using lucene syntax https //lucene apache org/core/2 9 4/queryparsersyntax html to match the relevant events for additional guidance on writing queries, see queries docid\ p1kznpx y9g6yp2crvssv and building advanced queries docid 8ykwptlf5d76xqwa1fwyv select one or more event categories and assign the severity level to apply to all matched events to give the rule precedence over any other rule that matches the same event, enable the make this an override toggle for more information, see how severity is calculated docid\ ltsdxtp9ncx7 fohtdsmk use the active toggle to activate or deactivate the rule click save to apply your changes how severity is calculated when an event is matched to your identifiers, it is checked against every flare severity rule and any custom severity rules you have defined every active rule that matches is considered to determine the event's final severity to understand how the final severity is decided, it is important to know that every rule behaves in one of two ways, depending on the override toggle a set rule is a rule with the override option disabled it proposes a severity, which is applied directly when it is the only rule that matches when other rules also match, its severity is weighed against theirs to decide the final result an override rule is a rule with the override option enabled it forces its severity over any set rules that match the same event how a tie is settled if there are multiple set rules, but no override rule, the event takes the highest severity proposed by the set rules if an override rule matches, it wins, forcing its severity and ignoring any set rules if several override rules match, the one with lowest severity wins if there are no matching rules, the final severity is info example of multiple matching rules here is an example showing what happens when an event matches multiple rules match 1 match 2 final severity why set high set medium high the set rule with the highest severity wins set high override low low an override always wins over a set rule set medium override critical critical an override can raise severity as well as lower it override medium override critical medium when several overrides match, the lowest one wins the reason for every rule that was applied to an event is shown in the event details, so you can see exactly why an event received its severity level faqs do changes to a severity rule affect past events? no rule changes apply going forward only creating, editing, disabling, or overriding a rule does not recompute the severity of events that were already scored before the change is disabling or overriding a flare rule reversible? yes clearing the override, or turning the flare rule back on, restores the default behavior with no lasting side effects as noted above, events scored while the override was active are not rescored why do some of my rules appear as beta? some rules are flagged beta while still being validated in production these rules display a badge next to their name and may be tuned or adjusted based on how they perform across tenants