Views:
February 24, 2025—Detection Model Management now supports logical operators (AND, OR) when creating custom detection models with multiple filters.
The new logical operators let you specify whether alerts trigger when all filters meet their thresholds (AND) or when any filter meets its threshold (OR).
For more information, see Configure a custom model.
XDR Threat InvestigationDetection Model ManagementCustom Models