Skip to main content

I have a rule that previously generated detections, but now when I attempt to run a retro hunt, it is not generating any alerts.

Are you able to find events that the rule should be generating detections for via search? Any chance the rule uses reference lists that may have been changed?


Reply