Anomaly Detection

Anomaly Detection Overview

The Anomaly Detection process executes correlation alerts according to the schedule defined for each alert. A correlation alert looks back over a specified period of time to determine if a condition has been satisfied (an excessive number of failed logins, for example) See Correlation Alerts for more information.

In a Central Manager environment, the Anomaly Detection panel is used to turn off correlation alerts that are not appropriate for a particular appliance. Under Central Management, all correlation alerts are defined on the Central Manager, and when activated, will be activated on all appliances by default.

Notes

Automatically activate Anomaly Detection on startup

  1. Click Administration Console > Anomaly Detection to open the Anomaly Detection panel.

  2. Mark the Active on Startup checkbox. Each time the appliance restarts, Anomaly Detection will be activated automatically.

  3. Click Apply.

  4.  Back to top.

Set the frequency that Anomaly Detection checks for appliance issues

  1. Click Administration Console > Anomaly Detection to open the Anomaly Detection panel.

  2. Enter the Polling Interval, in minutes.

  3. Click Apply.

  4.  Back to top.

Enable or Disable Active Alerts

To disable an alert globally in a Central Manager environment, it will be easier to clear the Active checkbox in the Modify Alert panel (see Correlation Alerts).

To enable or disable an alert on a single appliance in a Central Management environment, follow the procedure outlined below:

  1. Log in to the administrator portal of the appliance on which you want to disable one or more alerts.

  2. Click Administration Console > Anomaly Detection to open the Anomaly Detection panel.

  3. To disable an alert, select it from the Active Alerts box, and click Disable.

  4. To enable an alert, select it from the Locally Disabled Alerts box, and click Enable.

  5.  Back to top.

Stop or Restart Anomaly Detection

  1. Click Administration Console > Anomaly Detection to open the Anomaly Detection panel.

  2. Click Stop to stop Anomaly Detection, or click Restart to restart it.

  3.  Back to top.