Rule run frequency impacts the latency with which detections are discovered for
each rule. Longer run frequencies increase the amount of time between when an
event occurs and when a detection is processed for that event.
For details, see
Detection latencies.
To specify the run frequency for a rule, complete the following steps:
Navigate to the Rules Dashboard.
Open the rule options menu.
Click Run frequency.
Choose one of the Run frequency values.
Near Real-time: Single-event rules can be executed over data in streaming
fashion. The detection engine executes rules as soon as data is processed.
10 min: For multi-event rules, choose this frequency if you want your
detections as soon as possible.
1 hr: Detections begin to process after 1-2 hours, after which they are
subject to normal detection latency.
24 hrs: Detections begin to process after 24 hours, after which they
are subject to normal detection latency.
Multi-event rules with a window size of one hour or greater are
limited to the 1 hr and 24 hrs run frequencies.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-29 UTC."],[[["\u003cp\u003eRule run frequency affects how quickly detections are discovered, with longer frequencies increasing the time between an event and its detection.\u003c/p\u003e\n"],["\u003cp\u003eYou can set the run frequency for a rule in the Rules Dashboard by accessing the rule options menu and selecting from the available frequencies.\u003c/p\u003e\n"],["\u003cp\u003eNear Real-time frequency allows single-event rules to execute immediately upon data processing, while 10 min is for the quickest detection of multi-event rules.\u003c/p\u003e\n"],["\u003cp\u003eThe 1 hr and 24 hrs frequencies start processing detections after 1-2 hours and 24 hours, respectively, followed by normal detection latency.\u003c/p\u003e\n"],["\u003cp\u003eMulti-event rules that have a window size greater than one hour can only use 1 hr or 24 hrs as run frequencies.\u003c/p\u003e\n"]]],[],null,["Set the run frequency \nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nRule run frequency impacts the latency with which detections are discovered for\neach rule. Longer run frequencies increase the amount of time between when an\nevent occurs and when a detection is processed for that event.\nFor details, see\n[Detection latencies](/chronicle/docs/detection/run-rule-live-data#detection_latencies).\n\nTo specify the run frequency for a rule, complete the following steps:\n\n1. Navigate to the Rules Dashboard.\n\n2. Open the rule options menu.\n\n3. Click **Run frequency**.\n\n4. Choose one of the **Run frequency** values.\n\n - **Near Real-time**: Single-event rules can be executed over data in streaming fashion. The detection engine executes rules as soon as data is processed.\n - **10 min**: For multi-event rules, choose this frequency if you want your detections as soon as possible.\n - **1 hr**: Detections begin to process after 1-2 hours, after which they are subject to normal detection latency.\n - **24 hrs**: Detections begin to process after 24 hours, after which they are subject to normal detection latency.\n\n Multi-event rules with a window size of one hour or greater are\n limited to the **1 hr** and **24 hrs** run frequencies.\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]