Google Security Operations 规则(也称为精选检测)是由 Google Cloud 威胁情报 (GCTI) 创建的规则集,供 Google SecOps 客户使用。Google SecOps 规则容量限制了 Google SecOps 账号中可在任何给定时间启用的规则集数量。
每个规则集都有分配的容量值。为规则集启用任何规则(精确规则、宽泛规则或两者兼有)后,该规则集的容量便会用尽,并计入 Google SecOps 规则容量。如果账号已达到 Google SecOps 规则容量上限,则无法启用其他规则集。Google SecOps 账号的默认 Google SecOps 规则容量为 150 个。
Google SecOps 规则容量不是计数,而是分配给规则集的权重。规则集的权重取决于其复杂性。规则集越复杂,权重就越高。规则集的权重还受规则集处理的事件数量的影响。处理更多事件的规则集的权重更高。
如果您超出精选规则的容量上限,则可以继续运行现有规则,但无法创建新规则。如果您需要更大的容量,请与您的 Google SecOps 客户支持团队联系。
查看容量详情
精选检测页面上的规则集标签页会显示容量列和精选检测容量按钮(位于右上角)。
规则集的容量值表示规则集的总容量。如果规则集已启用,则该规则集的容量已满。当规则集的精确规则或宽泛规则(或两者)处于启用状态时,该规则集即被视为处于启用状态。当规则集的容量用尽时,该容量会计入 Google SecOps 账号的 Google SecOps 规则容量。例如,如果规则集 A 的容量为 8,规则集 B 的容量为 7,则 Google SecOps 规则总容量为 15。如果 Google SecOps 规则容量为 150,则规则集容量为 15/150。如需查看账号的 Google SecOps 规则容量,请点击精选检测容量状态按钮。达到 Google SecOps 规则容量上限后,您将无法再启用其他规则集。
在启用所有规则集之前,请检查容量
您可以启用所有规则集中的所有规则。不过,执行此操作需要您的账号具有经过人工审核的检测功能,且支持启用您账号的所有规则集。如需详细了解如何查看所有规则集的容量,以确保启用后它们的总容量不会超过可用的 Google SecOps 规则总容量,请查看容量详情。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-05-20。"],[[["Google Security Operations Rules, or curated detections, are rule sets from Google Cloud Threat Intelligence (GCTI) used by Google Security Operations customers, with a default capacity limit of 150 per account."],["The capacity of a rule set is determined by its complexity and the number of events it processes, with more complex rule sets and those processing more events having a higher weight, contributing towards the total capacity."],["Enabling a rule set, which can include Precise rules, Broad rules, or both, means its full capacity is counted toward the Google Security Operations Rules capacity, and additional rule sets cannot be enabled if this capacity limit is reached."],["You can check the capacity details of individual rule sets in the \"Detection \u003e Rules & Detections\" section, and you can view the total Google Security Operations Rules capacity for your account by clicking the \"Curated Detections Capacity\" button."],["It's possible to enable all rules across all rule sets, provided that the combined capacity of all rule sets does not exceed the account's total Google Security Operations Rules capacity of 150."]]],[]]