States are the highest logic level of a CAE rule and have a larger number of required fields.
This field contains a list of the objects that are used to define artifacts of interest within a state. For more information, see Artifacts of interest.
This field defines how long
CylanceOPTICSwill wait for events to trigger the event. The recommended default value is -0:00:00:001.
This field contains the field operators and operands that should be inspected to fulfill the function that is defined in the state. For more information, see Field operators.
This field defines which event categories, subcategories, and types that
CylanceOPTICSshould inspect when trying to fulfill a state. For more information, see Filters.
This field contains the logic function that
CylanceOPTICSmust observe to consider a state to be satisfied. For more information, see Functions.
This field defines whether
CylanceOPTICSshould record the events that satisfy a state. The recommended value is true.
This field defines the name of the state that will be displayed in the UI if the rule is satisfied.
This field defines the scope in which
CylanceOPTICSlooks for relevant events. In most cases, the recommended value is global.
This field contains a list of one or more state objects. These objects can be chained.