The Behavior Analytics Rules dashboard lists Active Rules and Disabled Rules, and provides a detailed History of all current and former Behavior Analytics Rules. You can create new Behavior Analytics Rules and manage existing rules from this dashboard.

The Behavior Analytics Rules dashboard contains the following tabs:

  • Active Rules

  • Disabled Rules

  • History

The Behavior Analytics Rules dashboard also provides the following features for better navigation and user experience:

  • Pagination: Lets you switch between the pages of information by using the left and right arrow keys at the bottom of the page. By default, ten rows are displayed on each page.

  • Sorting: Useful for viewing the content in ascending or descending order.

  • Drill-down: Lets you get additional details from the tabular views in the application.

NOTE: An exclamation mark icon is displayed beside the last run date (column) of any rules which haven't executed successfully. (If this occurs, you can check the system logs. Refer to the Configuration sections in the iManage Threat Manager Administration Help.)

In this section:

Active Rules

NOTE: To perform any of these operations on an active rule listed in the Active Rules tab, select it and then select from the options View, Edit, Run Now, Disable, or Delete.

View active rules

You can view the details of an active rule by either:

  • Selecting the rule row and clicking View

  • Drilling down by selecting the rule name in the Active Rules list

Both actions open the Rule Details and History tabs for the selected rule.

Rule Details tab

Provides the following information:

  • Applied included and excluded users/groups (total users/groups covered)

  • Effective scope, type, and run frequency

  • Time zone

  • Notify setting

  • Notification List shows all recipients.

  • Threshold date range and activity-specific thresholds

Threshold adjustments are indicated by icons that show when:

  • A group threshold is pinned for an activity.

  • A group threshold is pinned and set to Always raise an Urgent Alert when exceeded.

  • A group threshold is dynamic, with the number of standard deviations from the group mean manually adjusted.

  • Thresholds are ignored (marked with -- ), so alerts are based only on individual user deviations.

Hover over any icon to view a tooltip with details of the adjustment.

History tab

Shows a log of all actions performed on the rule, including:

  • Date and time of each action

  • Action type and the user who performed it

  • Any related comments. The Comment column accommodates entries of up to 2,000 characters, and each comment may be selected to view the full text.

Selecting a row displays a Rule Summary sidebar with a snapshot of the rule changes for that action.

Edit active rules

  1. Select the row of the rule that you want to edit and select Edit. Alternatively, select inside of the row of the rule you want to edit, and then Edit Rule to start editing the rule. The Edit Behavior Analytics Rule page appears.

  2. Change the rule as required. (For details on editable rule parameters, refer to Creating a Behavior Analytics Rule.)

  3. Select Update to save your changes to the rule.

You can also edit a rule from these tabs:

  • Active Rules: Select the Rule Name and select Edit Rule.

  • Disabled Rules: Select the Rule Name and select View. Then select Edit Rule.

  • History: Select the Rule Name and select Edit Rule.

NOTE: While it is possible to edit active and disabled rules, you can't edit deleted rules.

Run active rules on demand

Select the row of the rule that you want to run and select Run Now.

You can run a rule on demand even if it is scheduled. Running it manually doesn't affect its schedule. However, if you run a Scheduled rule manually before its first scheduled run, the system treats the on-demand run as the rule’s first run. In that case, the rule scans data and raises alerts based on its Behavior Analytics Alerts from the last [...] days setting.

Disable active rules

  1. Select the row of the rule that you want to disable and select Disable.

  2. You must provide a reason for disabling the rule and select Save. The list of active rules is refreshed and the disabled rule is no longer listed under the Active Rules tab. It is now listed under the Disabled Rules tab. From the time of its disablement, the disabled rule can no longer be used for report generation.

A disabled rule can be reactivated, if required, at any point in time. To do so:

  1. Select within the row of the disabled rule in the Disabled Rules tab.

  2. Select Activate.

    Now, the rule is seen listed in the Active Rules tab and the rule starts to generate reports or addressable alerts (that is, alerts generated by Continuous or Scheduled type rules, displayed in the Behavior Analytics Alert List), from the time that it’s activated, per the configured rule scheduling.

Delete active rules

  1. Select the row of the rule that you want to delete and select Delete. The Delete Rule confirmation pop-up window appears. The pop-up window displays a warning to inform you that this action can't be undone or reversed.

  2. Select OK. The rule is deleted. The History tab is updated to show the deleted rules.

  3. In the History tab, select the rule to drill down and see the Rule Details tab and the History tab with a list of actions performed on the rule and other details.

  4. Select a row in the History list and additional details are displayed in the sidebar.

Disabled Rules

You can perform the following operations from this tab:

View disabled rules

  1. The row of the disabled rule that you want to view and select View. The Rule Details and History tab are displayed for that rule. You can edit (and reactivate) disabled rules, but you can't edit deleted rules.

  2. In the Rule Details or History page of that rule, select Edit Rule at the upper right-hand side of the page. The Behavior Analytics Rule appears in edit mode.

  3. Make the required changes and select Update to save any changes to the rule.

NOTE: When you select Update, the rule will be activated, and can be seen listed in the Active Rules tab.

Activate disabled rules

It's possible to resume or activate a disabled rule at any time.

  1. Select the row of the disabled rule that you want to activate and select Activate.

    The system prompts you to enter a reason for modifying a rule. Now, the rule is seen listed in the Active Rules tab and the rule starts to generate reports or addressable alerts (that is, alerts generated by Continuous or Scheduled type rules, displayed in the Behavior Analytics Alert List) from the time that it’s activated, and according to the schedule defined in the rule. (For more information, refer to Active Rules). The History tab is updated to show the enabled rules.

  2. In the History tab, select the rule to drill down and see the Rule Details and History tabs with a list of actions performed on the rule and other details.

  3. Select a row in the History list and additional details are displayed in the sidebar.

NOTE: You can also edit and activate disabled rules in a single step. Refer to View disabled rules.

Delete disabled rules

  1. Select the row of the disabled rule that you want to delete and select Delete. The Delete Rule confirmation pop-up window appears. The pop-up window displays a warning to inform you that this action can't be undone or reversed.

  2. Select OK. The rule is deleted. The History tab is updated to show the deleted rules.

  3. In the History tab, select the rule to drill down and see the Rule Details and History tabs with a list of actions performed on the rule and other details. Select a row in the History list and additional details are displayed in the sidebar.

History

You can perform the following operations from the History tab:

  • View the history of all Behavior Analytics Rules.

  • Drill down and view the Rule Specifics and History of actions performed for the selected rule.

The History tab lists all actions performed on all the rules: Rule Names, the Date, and Time when the action was performed, and comments, if any. The history table list is sorted to show the rules with the most recent activity on top of the list. If you select a specific rule (row), then the Rule Details tab and History tab are displayed. These provide more details about the selected rule. Every activity about a rule is tracked in the History tab for that rule. The following information and actions are available by tab:

  • Rule Details: Provides a summary of the rule with details about Effective Included Users (that is, the total number of users covered by the rule), Effective Excluded Users, Frequency (that the rule was run), Timezone, Notify (notification setting), Notification List (list of users who received notifications for the rule), Thresholds Date Range, and a summary of thresholds for different activities.

  • History: Traces all the actions performed on that rule, the date and time when the actions were performed on the rule, the User performing the action, and comments, if any.

  • Rule Summary details: Shown in the side bar when you select a rule (row) from the list in the History tab.