Google Security Operations 規則 (也稱為精選偵測) 是由 Google Cloud Threat Intelligence (GCTI) 建立的規則集,供 Google SecOps 客戶使用。Google SecOps 規則容量會限制 Google SecOps 帳戶在任何時間可啟用的規則集數量。
每個規則集都有指派的容量值。如果規則集啟用任何規則 (精確規則、廣泛規則或兩者),即代表已達到規則集的處理上限,並計入 Google SecOps 規則容量。如果帳戶已達到 Google SecOps 規則容量上限,就無法啟用其他規則集。Google SecOps 帳戶的預設 Google SecOps 規則容量為 150。
Google SecOps 規則容量並非計數,而是指派給規則集的權重。規則集的權重取決於複雜度。規則集越複雜,權重就越高。規則集處理的事件數量也會影響規則集的權重。處理較多事件的規則集權重較高。
如果超過精選規則的容量上限,您仍可繼續執行現有規則,但無法建立新規則。如需較高的容量,請與 Google SecOps 帳戶團隊聯絡。
查看容量詳細資料
「精選偵測項目」頁面的「規則集」分頁會顯示「容量」欄位和「精選偵測項目容量」按鈕 (位於右上角)。
規則集的容量值代表規則集的完整容量。如果規則集已啟用,就代表已達到規則集的處理上限。如果規則集已啟用精確規則、廣泛規則或兩者,系統就會將其視為已啟用。如果規則集達到容量上限,該容量會計入 Google SecOps 帳戶的 Google SecOps 規則容量。舉例來說,如果規則集 A 的容量為 8,且已達到上限,而規則集 B 的容量為 7,且已達到上限,則總共會計入 15 個 Google SecOps 規則容量。如果 Google SecOps 規則容量為 150,則規則集容量為 15/150。如要查看帳戶的 Google SecOps 規則容量,請按一下「精選偵測容量」狀態按鈕。達到 Google SecOps 規則上限後,就無法再啟用其他規則集。
啟用所有規則集前,請先檢查容量
您可以啟用所有規則集的所有規則。不過,這項操作需要帳戶具備可支援啟用所有規則集的精選偵測容量。如要查看所有規則集的容量,確保啟用時的總容量不會超過 Google SecOps 規則總容量,請參閱容量詳細資料。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-07-16 (世界標準時間)。"],[[["Google Security Operations Rules, or curated detections, are rule sets from Google Cloud Threat Intelligence (GCTI) used by Google Security Operations customers, with a default capacity limit of 150 per account."],["The capacity of a rule set is determined by its complexity and the number of events it processes, with more complex rule sets and those processing more events having a higher weight, contributing towards the total capacity."],["Enabling a rule set, which can include Precise rules, Broad rules, or both, means its full capacity is counted toward the Google Security Operations Rules capacity, and additional rule sets cannot be enabled if this capacity limit is reached."],["You can check the capacity details of individual rule sets in the \"Detection \u003e Rules & Detections\" section, and you can view the total Google Security Operations Rules capacity for your account by clicking the \"Curated Detections Capacity\" button."],["It's possible to enable all rules across all rule sets, provided that the combined capacity of all rule sets does not exceed the account's total Google Security Operations Rules capacity of 150."]]],[]]