Skip to content

Security Check Anomaly Detection


Used to monitor potential vulnerabilities, anomalies, and risks in components such as systems, containers, and networks within the workspace. You can configure alerts by setting the trigger count for detection metrics, so that security threats can be promptly discovered and managed.

Use Cases

Supports monitoring vulnerabilities, anomalies, and risks in Network, Storage, Database, System, Webserver, and Container.

Detection Configuration

Detection Frequency

The execution frequency of detection rules; 5 minutes is selected by default.

Detection Range

The time range for detection metric queries. The available detection ranges vary depending on the detection frequency.

Detection Frequency Detection Range (Dropdown Options)
30s 1m/5m/15m/30m/1h/3h
1m 1m/5m/15m/30m/1h/3h
5m 5m/15m/30m/1h/3h
15m 15m/30m/1h/3h/6h
30m 30m/1h/3h/6h
1h 1h/3h/6h/12h/24h
6h 6h/12h/24h
12h 12h/24h
24h 24h

Detection Metrics

Monitors the number of inspection events that contain the configured fields in Security Check within a specified time range. Supports adding tag filters for filtering.

Field Description
Category Event category. Supported values: network, storage, database, system, webserver, container
Host Host name
Level Inspection event level. Supported values: info, warn, critical
Tags Filters the data of detection metrics based on metric tags, limiting the data scope of detection. Supports adding one or more tag filters, with fuzzy match and fuzzy not match filter conditions.
Detection Dimensions Any string type (keyword) field in the configured data can be selected as a detection dimension. Currently, up to three fields can be selected as detection dimensions. Through the combination of multiple detection dimension fields, a specific detection object can be determined. Guance determines whether the statistical metric corresponding to a detection object meets the threshold of the trigger condition. If the condition is met, an event is generated.

(For example, if the detection dimensions host and host_ip are selected, the detection object can be {host: host1, host_ip: 127.0.0.1}.)

Trigger Conditions

Set trigger conditions for alert levels: you can configure any one of Critical, Important, Warning, or Info trigger conditions.

Configure the trigger condition and severity level. When the query returns multiple values, an event is generated if any value satisfies the trigger condition.

For more details, see Event Level Description.

If consecutive trigger evaluation is enabled, you can configure the trigger condition to remain effective for multiple consecutive evaluations before an event is triggered again. The maximum is 10 times.

Alert Levels
  1. Alert Levels: Fatal, Severe, Important, Warning;

  2. Alert Level: Info: Based on the configured detection count, described as follows:

    • Each execution of a detection task counts as 1 detection. For example, if Detection Frequency = 5 minutes, then 1 detection = 5 minutes.
    • The detection count can be customized. For example, if Detection Frequency = 5 minutes, then 3 detections = 15 minutes.

After the detection rule takes effect, once Fatal, Severe, Important, or Warning anomaly events are generated, if the data detection result returns to normal within the configured custom detection period, a recovery alert event is generated.

Data Gap

Seven strategies can be configured for the data gap state.

  1. Linked to the detection range, evaluate the query result of the detection metric in the most recent minutes. No event is triggered.

  2. Linked to the detection range, evaluate the query result of the detection metric in the most recent minutes. The query result is treated as 0. In this case, the query result will be compared again with the thresholds configured in Trigger Conditions above to determine whether an anomaly event is triggered.

  3. Custom fill for the detection range value: triggers data gap events, Critical events, Important events, Warning events, and recovery events. When selecting this type of configuration strategy, the custom data gap time is recommended to be >= the detection range interval. If the configured time is <= the detection range interval, the data gap and anomaly conditions may be satisfied simultaneously. In this case, only the data gap processing result is applied.

Info Event Generation

After this option is enabled, detection results that do not match the trigger conditions above will be written as "Info" events.

Note

When trigger conditions, data gap, and info event generation are configured simultaneously, the trigger priority is determined as follows: Data Gap > Trigger Conditions > Info Event Generation.

Other Configuration

For more details, see Rule Configuration.

Feedback

Is this page helpful?