Skip to content

Commit daf3267

Browse files
authored
Merge pull request #189430 from Yvonne-deQ/patch-6
Update cloudknox-product-rule-based-anomalies.md
2 parents 043a85f + d6bcc5e commit daf3267

File tree

1 file changed

+20
-20
lines changed

1 file changed

+20
-20
lines changed

articles/active-directory/cloud-infrastructure-entitlement-management/cloudknox-product-rule-based-anomalies.md

Lines changed: 20 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -29,28 +29,29 @@ Rule-based anomalies identify recent activity in CloudKnox Permissions Managemen
2929

3030
- **Alert name**: Lists the name of the alert.
3131

32-
- To view the specific identity, resource, and task names that occurred during the alert collection period, select the **Alert Name**.
32+
- To view the specific identity, resource, and task names that occurred during the alert collection period, select the **Alert Name**.
3333

3434
- **Anomaly alert rule**: Displays the name of the rule select when creating the alert.
3535
- **# of occurrences**: How many times the alert trigger has occurred.
36-
- **Task**: How many tasks are affected by the alert.
37-
- **Resources**: How many resources are affected by the alert.
38-
- **Identity**: How many identities are affected by the alert.
36+
- **Task**: How many tasks performed are triggered by the alert.
37+
- **Resources**: How many resources accessed are triggered by the alert.
38+
- **Identity**: How many identities performing unusual behavior are triggered by the alert.
3939
- **Authorization system**: Displays which authorization systems the alert applies to, Amazon Web Services (**AWS**), Microsoft **Azure**, or Google Cloud Platform (**GCP**).
4040
- **Date/Time**: Lists the date and time of the alert.
4141
- **Date/Time (UTC)**: Lists the date and time of the alert in Coordinated Universal Time (UTC).
42-
- **View trigger**: Displays the current trigger settings and applicable authorization system details.
43-
- **Activity**: Displays details about the **Identity Name**, **Resource Name**, **Task Name**, **Date**, and **IP Address**.
42+
4443

4544
1. To filter alerts:
4645

4746
- From the **Alert Name** dropdown, select **All** or the appropriate alert name.
4847
- From the **Date** dropdown menu, select **Last 24 Hours**, **Last 2 Days**, **Last Week**, or **Custom Range**, and select **Apply**.
4948

50-
- If you select **Custom Range**, also enter **From** and **To** duration settings.
49+
- If you select **Custom Range**, also enter **From** and **To** duration settings.
5150
1. To view details that match the alert criteria, select the ellipses (**...**).
5251

53-
For example, **Authorization System Type**, **Authorization Systems**, **Resources**, **Tasks**, and **Identities**.
52+
- **View Trigger**: Displays the current trigger settings and applicable authorization system details
53+
- **Details**: Displays details about **Authorization System Type**, **Authorization Systems**, **Resources**, **Tasks**, **Identities**, and **Activity**
54+
- **Activity**: Displays details about the **Identity Name**, **Resource Name**, **Task Name**, **Date/Time**, **Inactive For**, and **IP Address**. Selecting the "eye" icon displays the **Raw Events Summary**
5455

5556
## Create a rule-based anomaly trigger
5657

@@ -63,11 +64,11 @@ Rule-based anomalies identify recent activity in CloudKnox Permissions Managemen
6364
1. Select one of the following conditions:
6465
- **Any Resource Accessed for the First Time**: The identity accesses a resource for the first time during the specified time interval.
6566
- **Identity Performs a Particular Task for the First Time**: The identity does a specific task for the first time during the specified time interval.
66-
- **Inactive Identity Becomes Active**: An identity that hasn't been active for 90 days becomes active and does any task in the selected time interval.
67+
- **Identity Performs a Task for the First Time**: The identity performs any task for the first time during the specified time interval
6768
1. Select **Next**.
68-
1. On the **Authorization systems** tab, select the available authorization systems accounts and folders, or select **All**.
69+
1. On the **Authorization Systems** tab, select the available authorization systems and folders, or select **All**.
6970

70-
This screen defaults to **List** view, but you can change it to **Folder** view. You can select the applicable folder instead of individually by system.
71+
This screen defaults to **List** view, but you can change it to **Folders** view. You can select the applicable folder instead of individually selecting by authorization system.
7172

7273
- The **Status** column displays if the authorization system is online or offline.
7374
- The **Controller** column displays if the controller is enabled or disabled.
@@ -82,14 +83,13 @@ Rule-based anomalies identify recent activity in CloudKnox Permissions Managemen
8283

8384
The **Alert triggers** subtab displays the following information:
8485

85-
- **Alert**: Displays the name of the alert.
86+
- **Alerts**: Displays the name of the alert.
8687
- **Anomaly Alert Rule**: Displays the name of the selected rule when creating the alert.
8788
- **# of users subscribed**: Displays the number of users subscribed to the alert.
8889
- **Created by**: Displays the email address of the user who created the alert.
89-
- **Last modified by**: Displays the email address of the user who last modified the alert.
90-
- **Last modified on**: Displays the date and time the trigger was last modified.
91-
- **Subscription**: Switches between **On** and **Off**.
92-
- **View Trigger**: Displays the current trigger settings and applicable authorization system details.
90+
- **Last Modified By**: Displays the email address of the user who last modified the alert.
91+
- **Last Modified On**: Displays the date and time the trigger was last modified.
92+
- **Subscription**: Subscribes you to receive alert emails. Switches between **On** and **Off**.
9393

9494
1. To view other options available to you, select the ellipses (**...**), and then select from the available options:
9595

@@ -99,16 +99,16 @@ Rule-based anomalies identify recent activity in CloudKnox Permissions Managemen
9999

100100
Only the user who created the alert can edit the trigger screen, rename an alert, deactivate an alert, and delete an alert. Changes made by other users aren't saved.
101101

102-
- **Duplicate**: Create a duplicate of the alert called "**Copy of XXX**".
102+
- **Duplicate**: Create a duplicate copy of the selected alert trigger.
103103
- **Rename**: Enter the new name of the query, and then select **Save.**
104104
- **Deactivate**: The alert will still be listed, but will no longer send emails to subscribed users.
105105
- **Activate**: Activate the alert trigger and start sending emails to subscribed users.
106-
- **Notification settings**: View the **Email** of users who are subscribed to the alert trigger and their **User status**.
106+
- **Notification settings**: View the **Email** of users who are subscribed to the alert trigger.
107107
- **Delete**: Delete the alert.
108108

109109
If the **Subscription** is **Off**, the following options are available:
110110
- **View**: View details of the alert trigger.
111-
- **Notification settings**: View the **Email** of users who are subscribed to the alert trigger and their **User status**.
111+
- **Notification settings**: View the **Email** of users who are subscribed to the alert trigger.
112112
- **Duplicate**: Create a duplicate copy of the selected alert trigger.
113113

114114
1. To filter by **Activated** or **Deactivated**, in the **Status** section, select **All**, **Activated**, or **Deactivated**, and then select **Apply**.
@@ -120,4 +120,4 @@ Rule-based anomalies identify recent activity in CloudKnox Permissions Managemen
120120
- For an overview on activity triggers, see [View information about activity triggers](cloudknox-ui-triggers.md).
121121
- For information on activity alerts and alert triggers, see [Create and view activity alerts and alert triggers](cloudknox-howto-create-alert-trigger.md).
122122
- For information on finding outliers in identity's behavior, see [Create and view statistical anomalies and anomaly triggers](cloudknox-product-statistical-anomalies.md).
123-
- For information on permission analytics triggers, see [Create and view permission analytics triggers](cloudknox-product-permission-analytics.md).
123+
- For information on permission analytics triggers, see [Create and view permission analytics triggers](cloudknox-product-permission-analytics.md).

0 commit comments

Comments
 (0)