
WANGUARD 5.2 User Manual & Administrator's Guide
2
Anomaly ID
Number
{anomaly_id}
The unique identfcaton number of the
anomaly.
3
Anomaly Comment
String
{comment}
The comment added in Console by
Administrators for the Anomaly.
4
Directon [incoming,outgoing]
String
{direction}
The directon of the rule that triggered the
anomaly. Can be “incoming” or “outgoing”.
5
Domain [ip,subnet]
String
{domain}
It's “ip” when CIDR = 32 for IPv4 or 128 for
IPv6. It's “subnet” otherwise.
6
Anomaly Class [thresholds,profle] String
{class}
It's “thresholds” for threshold-based
anomalies or “profle” for profling-based
anomalies.
7
Threshold Type
[absolute,percentage]
String
{threshold_type}
Threshold-based anomalies can be defned
as “absolute” values or as a “percentage”
of the total trafc received by the Sensor.
8
Anomaly Decoder (Protocol)
[TOTAL,...]
String
{decoder}
The trafc decoder (protocol) for the
detected anomaly.
9
Comparison [above,under]
String
{operation}
It's “above” for exceeding thresholds or
“under” for the less-than-expected
thresholds.
10
Unit [pkts/s,bits/s]
String
{unit}
It's “pkts/s” for packets per second
anomalies or “bits/s” for bits per second
anomalies.
11
Threshold Value
Number*
{rule_value}
It's the threshold value confgured for the
threshold.
12
Computed Threshold
Number*
{computed_threshold}
It's the threshold of the anomaly. It's
dynamically adjusted for profling-based
and percentage-based anomalies.
13
Peak Value
Number*
{value}
The highest value of the trafc decoder for
“above” thresholds or the lowest value for
the “under” thresholds.
14
Latest Value
Number*
{latest_value}
The latest value given by the trafc
decoder that detected the anomaly.
15
Sum Value
Number*
{sum_value}
The sum of the values given by the trafc
decoder as long as the anomaly is actve.
16
Peak Rule Severity
Number
{severity}
The feld contains the rato between the
peak anomalous trafc rate and the
threshold value.
17
Latest Rule Severity
Number
{latest_severity}
The feld contains the rato between the
latest anomalous trafc rate and the
threshold value.
18
Peak Link Severity
Number
{link_severity}
The feld contains the rato between the
peak anomalous trafc rate and the
interface's trafc rate.
- 36 -
Содержание Wanguard 5.2
Страница 1: ......