Change the State of a Continuous Detection and Response Event

A Continuous Detection and Response (CDR) event can be in one of these states:

  • Active, which means that all new inbound messages will be compared to the conditions in this CDR event, and the CDR event action will be applied to all matching messages. (See Modify a Continuous Detection and Response Event Action to change the defined action.) This is the default when a new event is created.
  • Inactive, which means that CDR does not check for messages that might match this event. CDR events can manually be set to inactive when it is determined that they are no longer a threat.
  • Pending, which means that the event has been created, but not published. If an event remains in the Pending state for more than four hours it has likely failed and will not become active. The best course of action is to rewrite the rule to make it less complex, for example by breaking it into several simpler rules. Pending rules will not show as Failed but will remain labeled as Pending until deleted.

You change the state in a CDR event's details page.

Change the state of a continuous detection and response event in Cloud Email Protection

  1. Go to Manage > Continuous Detection.
  2. Click an event Name.
  3. At the top of the CDR Details page, click the Inactive/Active toggle.