Security Check Anomaly Detection¶
Used to monitor potential vulnerabilities, anomalies, and risks in components such as systems, containers, and networks within the workspace. You can configure alerts by setting the trigger count for detection metrics, so that security threats can be promptly discovered and managed.
Use Cases¶
Supports monitoring vulnerabilities, anomalies, and risks in Network, Storage, Database, System, Webserver, and Container.
Detection Configuration¶
Detection Frequency¶
The execution frequency of detection rules; 5 minutes is selected by default.
Detection Range¶
The time range for detection metric queries. The available detection ranges vary depending on the detection frequency.
| Detection Frequency | Detection Range (Dropdown Options) |
|---|---|
| 30s | 1m/5m/15m/30m/1h/3h |
| 1m | 1m/5m/15m/30m/1h/3h |
| 5m | 5m/15m/30m/1h/3h |
| 15m | 15m/30m/1h/3h/6h |
| 30m | 30m/1h/3h/6h |
| 1h | 1h/3h/6h/12h/24h |
| 6h | 6h/12h/24h |
| 12h | 12h/24h |
| 24h | 24h |
Detection Metrics¶
Monitors the number of inspection events that contain the configured fields in Security Check within a specified time range. Supports adding tag filters for filtering.
| Field | Description |
|---|---|
| Category | Event category. Supported values: network, storage, database, system, webserver, container |
| Host | Host name |
| Level | Inspection event level. Supported values: info, warn, critical |
| Tags | Filters the data of detection metrics based on metric tags, limiting the data scope of detection. Supports adding one or more tag filters, with fuzzy match and fuzzy not match filter conditions. |
| Detection Dimensions | Any string type (keyword) field in the configured data can be selected as a detection dimension. Currently, up to three fields can be selected as detection dimensions. Through the combination of multiple detection dimension fields, a specific detection object can be determined. Guance determines whether the statistical metric corresponding to a detection object meets the threshold of the trigger condition. If the condition is met, an event is generated.(For example, if the detection dimensions host and host_ip are selected, the detection object can be {host: host1, host_ip: 127.0.0.1}.) |
Trigger Conditions¶
Set trigger conditions for alert levels: you can configure any one of Critical, Important, Warning, or Info trigger conditions.
Configure the trigger condition and severity level. When the query returns multiple values, an event is generated if any value satisfies the trigger condition.
For more details, see Event Level Description.
If consecutive trigger evaluation is enabled, you can configure the trigger condition to remain effective for multiple consecutive evaluations before an event is triggered again. The maximum is 10 times.
Alert Levels
-
Alert Levels: Fatal, Severe, Important, Warning;
-
Alert Level: Info: Based on the configured detection count, described as follows:
- Each execution of a detection task counts as 1 detection. For example, if
Detection Frequency = 5 minutes, then 1 detection = 5 minutes. - The detection count can be customized. For example, if
Detection Frequency = 5 minutes, then 3 detections = 15 minutes.
- Each execution of a detection task counts as 1 detection. For example, if
After the detection rule takes effect, once Fatal, Severe, Important, or Warning anomaly events are generated, if the data detection result returns to normal within the configured custom detection period, a recovery alert event is generated.
Data Gap¶
Seven strategies can be configured for the data gap state.
-
Linked to the detection range, evaluate the query result of the detection metric in the most recent minutes. No event is triggered.
-
Linked to the detection range, evaluate the query result of the detection metric in the most recent minutes. The query result is treated as 0. In this case, the query result will be compared again with the thresholds configured in Trigger Conditions above to determine whether an anomaly event is triggered.
-
Custom fill for the detection range value: triggers data gap events, Critical events, Important events, Warning events, and recovery events. When selecting this type of configuration strategy, the custom data gap time is recommended to be >= the detection range interval. If the configured time is <= the detection range interval, the data gap and anomaly conditions may be satisfied simultaneously. In this case, only the data gap processing result is applied.
Info Event Generation¶
After this option is enabled, detection results that do not match the trigger conditions above will be written as "Info" events.
Note
When trigger conditions, data gap, and info event generation are configured simultaneously, the trigger priority is determined as follows: Data Gap > Trigger Conditions > Info Event Generation.
Other Configuration¶
For more details, see Rule Configuration.