You can start and stop network anomaly detection rules manually. Stopping or starting a rule is available only for enabled rules.
You cannot start a rule with the New, Pending, Awaiting data, or Running status.
To trigger the Network Anomaly Detection rule:
The details area is displayed in the right part of the web interface window.
The Configure rule run pane appears on the right. The upper part of the panel displays information about the available range for analyzing protocol attributes. The range is limited to the earliest and latest arrival of traffic data in the database used to store protocol attributes.
The network anomaly detection rule is started.
You can stop rules if they have one of the following statuses: New, Pending, Awaiting data, or Running.
To stop the execution of a network anomaly detection rule:
The details area is displayed in the right part of the web interface window.
The network anomaly detection rule is stopped.
Page top