> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Creating Rules from Events

USM Anywhere enables you to create and manage your own orchestration rules from the <Tooltip tip="Any traffic or data exchange detected by LevelBlue products through a sensor or external devices such as a firewall.">Events</Tooltip> details pages, which is the easiest way to configure an orchestration rule.

<Danger>
  **Warning:** Orchestration rules only apply to future events and alarms.

  Suppression rules using the Contains, Match and Match, case insensitive operators apply to future events and alarms, not to events and alarms received in the current day.
</Danger>

You can create these rules:

* **Suppression Rule**: See [Creating Suppression Rules from the Events Page](supression-rule) and [Suppression Rules from the Orchestration Rules Page](../rules-management/suppression-rules) for more information.

  <Note>
    **Note:** Users in the Investigator role can create suppression rules but cannot create filtering, alarm, or notification rules.
  </Note>

* **Filtering Rule**: See [Creating Filtering Rules from the Events Page](filtering-rule) and [Filtering Rules from the Orchestration Rules Page](../rules-management/filtering-rules) for more information.

  <Warning>
    **Important:** The **Create Filtering Rule** option is not visible if the Agent has sent the event.
  </Warning>

* **<Tooltip tip="Alarms provide notification of an event or sequence of events that require attention or investigation.">Alarm</Tooltip> Rule**: See [Creating Alarm Rules from the Events Page](alarm-rules) and [Correlation Rules](../rules-management/correlation-rules) for more information.

* **Notification Rule**: See [Creating Notification Rules from the Events Page](notification-rule) and [Correlation Rules](../rules-management/correlation-rules) for more information.
