如果您超出精选规则的容量上限,则可以继续运行现有规则,但无法创建新规则。如果您需要更高的容量,请与您的 Google Security Operations 客户支持团队联系。
查看容量详情
精选检测页面上的规则集标签页会显示容量列和精选检测容量按钮(右上角)。
规则集的容量值表示规则集的总容量。如果规则集已启用,则该规则集的容量已满。当规则集的精确规则或宽泛规则(或两者)处于启用状态时,该规则集即被视为处于启用状态。当规则集的容量用尽时,该容量会计入 Google Security Operations 账号的 Google Security Operations 规则容量。例如,如果规则集 A 的容量为 8,规则集 B 的容量为 7,则 Google 安全运营规则的总容量为 15。如果 Google Security Operations 规则容量为 150,则规则集容量为 15/150。如需查看账号的 Google Security Operations 规则容量,请点击精选检测容量状态按钮。达到 Google 安全运营规则容量上限后,您将无法再启用其他规则集。
在启用所有规则集之前,请检查容量
您可以启用所有规则集中的所有规则。不过,若要执行此操作,您的账号必须具备经过人工审核的检测功能,才能支持启用账号的所有规则集。如需详细了解如何查看所有规则集的容量,以确保启用后它们的总容量不会超过可用的 Google Security Operations 规则总容量,请查看容量详情。
如需启用所有规则集,请执行以下操作:
点击快捷操作下拉菜单。
选择完成建议的规则设置。
点击启用所有规则集的所有规则。
点击 Google Security Operations Rules Capacity 按钮(位于右上角),确认您的容量用量。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-04-02。"],[[["Google Security Operations Rules, or curated detections, are rule sets from Google Cloud Threat Intelligence (GCTI) used by Google Security Operations customers, with a default capacity limit of 150 per account."],["The capacity of a rule set is determined by its complexity and the number of events it processes, with more complex rule sets and those processing more events having a higher weight, contributing towards the total capacity."],["Enabling a rule set, which can include Precise rules, Broad rules, or both, means its full capacity is counted toward the Google Security Operations Rules capacity, and additional rule sets cannot be enabled if this capacity limit is reached."],["You can check the capacity details of individual rule sets in the \"Detection \u003e Rules & Detections\" section, and you can view the total Google Security Operations Rules capacity for your account by clicking the \"Curated Detections Capacity\" button."],["It's possible to enable all rules across all rule sets, provided that the combined capacity of all rule sets does not exceed the account's total Google Security Operations Rules capacity of 150."]]],[]]