Cloud security rule status for custom configuration rules - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-11
Category
Administrator Guide

Out-of-the-box and custom cloud security configuration rules are enabled by default, and can be manually disabled and reenabled as needed. Additionally, the system may change the status of custom configuration rules based on resource consumption.

The statuses of cloud security configuration rules are described in the table below.

Status

Description

Enabled

Indicates that the rule is working normally.

Moderated

Indicates that the rule is consuming higher than expected resources, so the system is executing the rule less frequently.You will receive an in-product notification if the status of a rule is changed to Moderated.

Suspended

Indicates that the rule has been suspended for exceeding the maximum allowed resource consumption.

You will receive an in-product notification if the status of a rule is changed to Suspended.

To reenable a suspended rule, you must update the query in the rule. After saving the updated rule, the status will automatically change to Enabled. If the updated rule continues to use excessive resources, the system will move it back into the Moderated or Suspended status.

Disabled

Indicates that the rule has been manually disabled.