You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-infrastructure-entitlement-management/cloudknox-product-rule-based-anomalies.md
- To view the specific identity, resource, and task names that occurred during the alert collection period, select the **Alert Name**.
32
+
- To view the specific identity, resource, and task names that occurred during the alert collection period, select the **Alert Name**.
33
33
34
34
-**Anomaly alert rule**: Displays the name of the rule select when creating the alert.
35
35
-**# of occurrences**: How many times the alert trigger has occurred.
36
-
-**Task**: How many tasks are affected by the alert.
37
-
-**Resources**: How many resources are affected by the alert.
38
-
-**Identity**: How many identities are affected by the alert.
36
+
-**Task**: How many tasks performed are triggered by the alert.
37
+
-**Resources**: How many resources accessed are triggered by the alert.
38
+
-**Identity**: How many identities performing unusual behavior are triggered by the alert.
39
39
-**Authorization system**: Displays which authorization systems the alert applies to, Amazon Web Services (**AWS**), Microsoft **Azure**, or Google Cloud Platform (**GCP**).
40
40
-**Date/Time**: Lists the date and time of the alert.
41
41
-**Date/Time (UTC)**: Lists the date and time of the alert in Coordinated Universal Time (UTC).
42
-
-**View trigger**: Displays the current trigger settings and applicable authorization system details.
43
-
-**Activity**: Displays details about the **Identity Name**, **Resource Name**, **Task Name**, **Date**, and **IP Address**.
42
+
44
43
45
44
1. To filter alerts:
46
45
47
46
- From the **Alert Name** dropdown, select **All** or the appropriate alert name.
48
47
- From the **Date** dropdown menu, select **Last 24 Hours**, **Last 2 Days**, **Last Week**, or **Custom Range**, and select **Apply**.
49
48
50
-
- If you select **Custom Range**, also enter **From** and **To** duration settings.
49
+
- If you select **Custom Range**, also enter **From** and **To** duration settings.
51
50
1. To view details that match the alert criteria, select the ellipses (**...**).
52
51
53
-
For example, **Authorization System Type**, **Authorization Systems**, **Resources**, **Tasks**, and **Identities**.
52
+
-**View Trigger**: Displays the current trigger settings and applicable authorization system details
53
+
-**Details**: Displays details about **Authorization System Type**, **Authorization Systems**, **Resources**, **Tasks**, **Identities**, and **Activity**
54
+
-**Activity**: Displays details about the **Identity Name**, **Resource Name**, **Task Name**, **Date/Time**, **Inactive For**, and **IP Address**. Selecting the "eye" icon displays the **Raw Events Summary**
-**Any Resource Accessed for the First Time**: The identity accesses a resource for the first time during the specified time interval.
65
66
-**Identity Performs a Particular Task for the First Time**: The identity does a specific task for the first time during the specified time interval.
66
-
-**Inactive Identity Becomes Active**: An identity that hasn't been active for 90 days becomes active and does any task in the selected time interval.
67
+
-**Identity Performs a Task for the First Time**: The identity performs any task for the first time during the specified time interval
67
68
1. Select **Next**.
68
-
1. On the **Authorization systems** tab, select the available authorization systems accounts and folders, or select **All**.
69
+
1. On the **Authorization Systems** tab, select the available authorization systems and folders, or select **All**.
69
70
70
-
This screen defaults to **List** view, but you can change it to **Folder** view. You can select the applicable folder instead of individually by system.
71
+
This screen defaults to **List** view, but you can change it to **Folders** view. You can select the applicable folder instead of individually selecting by authorization system.
71
72
72
73
- The **Status** column displays if the authorization system is online or offline.
73
74
- The **Controller** column displays if the controller is enabled or disabled.
Only the user who created the alert can edit the trigger screen, rename an alert, deactivate an alert, and delete an alert. Changes made by other users aren't saved.
101
101
102
-
-**Duplicate**: Create a duplicate of the alert called "**Copy of XXX**".
102
+
-**Duplicate**: Create a duplicate copy of the selected alert trigger.
103
103
-**Rename**: Enter the new name of the query, and then select **Save.**
104
104
-**Deactivate**: The alert will still be listed, but will no longer send emails to subscribed users.
105
105
-**Activate**: Activate the alert trigger and start sending emails to subscribed users.
106
-
-**Notification settings**: View the **Email** of users who are subscribed to the alert trigger and their **User status**.
106
+
-**Notification settings**: View the **Email** of users who are subscribed to the alert trigger.
107
107
-**Delete**: Delete the alert.
108
108
109
109
If the **Subscription** is **Off**, the following options are available:
110
110
-**View**: View details of the alert trigger.
111
-
-**Notification settings**: View the **Email** of users who are subscribed to the alert trigger and their **User status**.
111
+
-**Notification settings**: View the **Email** of users who are subscribed to the alert trigger.
112
112
-**Duplicate**: Create a duplicate copy of the selected alert trigger.
113
113
114
114
1. To filter by **Activated** or **Deactivated**, in the **Status** section, select **All**, **Activated**, or **Deactivated**, and then select **Apply**.
- For an overview on activity triggers, see [View information about activity triggers](cloudknox-ui-triggers.md).
121
121
- For information on activity alerts and alert triggers, see [Create and view activity alerts and alert triggers](cloudknox-howto-create-alert-trigger.md).
122
122
- For information on finding outliers in identity's behavior, see [Create and view statistical anomalies and anomaly triggers](cloudknox-product-statistical-anomalies.md).
123
-
- For information on permission analytics triggers, see [Create and view permission analytics triggers](cloudknox-product-permission-analytics.md).
123
+
- For information on permission analytics triggers, see [Create and view permission analytics triggers](cloudknox-product-permission-analytics.md).
0 commit comments