In Configuration > Settings > Activity Sets, users with the Configuration Manager role can create and manage activity sets. These sets are best-practice groups of activities purpose-built for:
Detecting potentially malicious behavior
Analyzing compliance patterns
Monitoring activity across a particular client or matter
In this section:
Activity sets
Three activity sets are available out of the box and are recommended. These can be customized when adding a rule or running a report:
Threat Monitor: Used by default when creating Behavior Analytics Rules and Outliers reports.
Compliance Indicating Activities: Used by default in Compliance > Adoption reports and when creating Compliance > Trending charts.
Activity Monitoring: Used by default when creating Matter Activity reports.
Activity sets are available for selection when working with the following:
Behavior Analytics Rules and reports
Matter Activity Rules and reports
Outliers reports
Analyze
Compliance > Adoption report
Compliance > Trending charts
Task: Create an activity set
You need the Configuration Manager role to complete this task.
Select Add Activity Set.
In the New Activity Set dialog, enter a name in the Name field. Use a name that reflects the possible threat or risk.
Select the check boxes next to the activities that you want to include.
Select Save. The new activity set appears on the Activity Sets page.
Task: Edit an activity set
You need the Configuration Manager role to complete this task.
Select (more options) > Edit in the row of the activity set that you want to edit.
Remove or add activities, then select Save.
Task: Delete an activity set
You need the Configuration Manager role to complete this task.
Select (more options) > Delete in the row of the activity set.
NOTE: Only user-created activity sets can be deleted.

