What a rule contains
A rule’s metric and scope are fixed once created; to change them, delete the rule and add a new one. The threshold and enabled status can be edited at any time.
Global defaults and your network’s overrides
Detection rules come in two scopes:- A global default applies to every network that does not have its own rule for that metric.
- A per-network override replaces the global default for your network, letting you tune a threshold to your fleet.
Adding a rule
To add an override for your network, open Settings → Detection Rules, choose the metric, set the scope to your network, and set the threshold. Enable it to start detection, or leave it disabled to stage it. Deleting your override reverts the metric to the global default.Changing a detection rule affects incidents opened after the change. It does not reopen or reclassify incidents that were already detected.Detection rules decide when incidents open; SLA rules decide how quickly they must be resolved, and auto-resolution decides how they close when the condition clears.