Sounds right.
Take a simple rule, logon failure. If you specify the event type, but nothing for source/destination machine, etc, it will apply to every machine/group.
If you want to limit it to a specific group, you need to add that into the rule correlation.