Google 資安營運規則 (也稱為精選偵測) 是由 Google Cloud 威脅情報 (GCTI) 建立的規則集,供 Google SecOps 客戶使用。Google SecOps 規則容量會限制 Google SecOps 帳戶在任何特定時間內可啟用的規則集數量。
每個規則集都有指派的處理上限值。當規則集啟用任何規則 (精確規則、廣泛規則或兩者皆是) 時,就會達到規則集的處理上限,並計入 Google SecOps 規則的處理上限。如果帳戶已達到 Google SecOps 規則容量上限,就無法啟用其他規則集。Google SecOps 帳戶的預設 Google SecOps 規則容量為 150。
Google SecOps 規則容量並非計數,而是指派給規則集的權重。規則集的權重取決於其複雜度。較複雜的規則集權重較高。規則集處理的事件數量也會影響規則集的權重。處理更多事件的規則集權重較高。
如果您超過精選規則的容量上限,可以繼續執行現有規則,但無法建立新規則。如需更大的容量,請與 Google SecOps 帳戶團隊聯絡。
查看容量詳細資料
「精選偵測項目」頁面中的「規則集」分頁會顯示「容量」欄和「精選偵測項目容量」按鈕 (右上方)。
規則集的容量值代表規則集的處理上限。如果已啟用規則集,就代表已達到規則集的處理上限。當精確規則、廣泛規則或兩者皆已啟用時,系統就會將規則集視為已啟用。當規則集的容量達到上限時,該容量會計入 Google SecOps 帳戶的 Google SecOps 規則容量。舉例來說,如果規則集 A 的容量為 8,而規則集 B 的容量為 7,則 15 會計入 Google SecOps 規則的總容量。如果 Google SecOps 規則容量為 150,則規則集容量為 15/150。如要查看帳戶的 Google SecOps 規則額度,請按一下「Curated Detections Capacity」狀態按鈕。達到 Google SecOps 規則上限後,就無法再啟用其他規則集。
啟用所有規則集前,請先檢查處理上限
您可以啟用所有規則集的所有規則。不過,您必須先在帳戶中啟用精選偵測功能,才能執行這項操作,這樣才能啟用帳戶的所有規則集。如要進一步瞭解如何查看所有規則集的容量,確保啟用時的總容量總和不會超過可用的 Google SecOps 規則容量,請參閱容量詳細資料。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-06-03 (世界標準時間)。"],[[["Google Security Operations Rules, or curated detections, are rule sets from Google Cloud Threat Intelligence (GCTI) used by Google Security Operations customers, with a default capacity limit of 150 per account."],["The capacity of a rule set is determined by its complexity and the number of events it processes, with more complex rule sets and those processing more events having a higher weight, contributing towards the total capacity."],["Enabling a rule set, which can include Precise rules, Broad rules, or both, means its full capacity is counted toward the Google Security Operations Rules capacity, and additional rule sets cannot be enabled if this capacity limit is reached."],["You can check the capacity details of individual rule sets in the \"Detection \u003e Rules & Detections\" section, and you can view the total Google Security Operations Rules capacity for your account by clicking the \"Curated Detections Capacity\" button."],["It's possible to enable all rules across all rule sets, provided that the combined capacity of all rule sets does not exceed the account's total Google Security Operations Rules capacity of 150."]]],[]]