Frekuensi menjalankan aturan memengaruhi latensi penemuan deteksi untuk
setiap aturan. Frekuensi eksekusi yang lebih lama akan meningkatkan jangka waktu antara saat peristiwa terjadi dan saat deteksi diproses untuk peristiwa tersebut.
Untuk mengetahui detailnya, lihat
Latensi deteksi.
Untuk menentukan frekuensi eksekusi aturan, selesaikan langkah-langkah berikut:
Buka Dasbor Aturan.
Buka menu opsi aturan.
Klik Run frequency.
Pilih salah satu nilai Frekuensi eksekusi.
Hampir Real-time: Aturan peristiwa tunggal dapat dijalankan pada data dalam gaya streaming. Mesin deteksi menjalankan aturan segera setelah data diproses.
10 menit: Untuk aturan multi-acara, pilih frekuensi ini jika Anda ingin deteksi sesegera mungkin.
1 jam: Deteksi mulai diproses setelah 1-2 jam, setelah itu deteksi tunduk pada latensi deteksi normal.
24 jam: Deteksi mulai diproses setelah 24 jam, setelah itu deteksi tunduk pada latensi deteksi normal.
Aturan multi-peristiwa dengan ukuran periode satu jam atau lebih dibatasi untuk frekuensi berjalan 1 jam dan 24 jam.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-21 UTC."],[[["\u003cp\u003eRule run frequency affects how quickly detections are discovered, with longer frequencies increasing the time between an event and its detection.\u003c/p\u003e\n"],["\u003cp\u003eYou can set the run frequency for a rule in the Rules Dashboard by accessing the rule options menu and selecting from the available frequencies.\u003c/p\u003e\n"],["\u003cp\u003eNear Real-time frequency allows single-event rules to execute immediately upon data processing, while 10 min is for the quickest detection of multi-event rules.\u003c/p\u003e\n"],["\u003cp\u003eThe 1 hr and 24 hrs frequencies start processing detections after 1-2 hours and 24 hours, respectively, followed by normal detection latency.\u003c/p\u003e\n"],["\u003cp\u003eMulti-event rules that have a window size greater than one hour can only use 1 hr or 24 hrs as run frequencies.\u003c/p\u003e\n"]]],[],null,["Set the run frequency \nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nRule run frequency impacts the latency with which detections are discovered for\neach rule. Longer run frequencies increase the amount of time between when an\nevent occurs and when a detection is processed for that event.\nFor details, see\n[Detection latencies](/chronicle/docs/detection/run-rule-live-data#detection_latencies).\n\nTo specify the run frequency for a rule, complete the following steps:\n\n1. Navigate to the Rules Dashboard.\n\n2. Open the rule options menu.\n\n3. Click **Run frequency**.\n\n4. Choose one of the **Run frequency** values.\n\n - **Near Real-time**: Single-event rules can be executed over data in streaming fashion. The detection engine executes rules as soon as data is processed.\n - **10 min**: For multi-event rules, choose this frequency if you want your detections as soon as possible.\n - **1 hr**: Detections begin to process after 1-2 hours, after which they are subject to normal detection latency.\n - **24 hrs**: Detections begin to process after 24 hours, after which they are subject to normal detection latency.\n\n Multi-event rules with a window size of one hour or greater are\n limited to the **1 hr** and **24 hrs** run frequencies.\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]