Configuring the Anomaly Detector service

In Kaspersky MLAD, an ML model can contain the following detectors:

You can configure the procedure for detecting anomalies based on the specific features of your monitored asset by enabling or disabling the necessary detectors in the Anomaly Detector service settings.

System administrators can configure the Anomaly Detector service.

To configure the settings of the Anomaly Detector service in Kaspersky MLAD:

  1. In the lower-left corner of the page, click the Main menu button.

    You will be taken to the administrator menu.

  2. Select System parametersAnomaly Detector.

    A list of options appears on the right.

  3. Enable or disable the Limit Detector using the Use Limit Detector toggle switch.
  4. Enable or disable the Forecaster detector using the Use Forecaster detector toggle switch.
  5. Enable or disable the XGBoost detector using the Use XGBoost detector toggle switch.
  6. Enable or disable use of the Rule Detector using the Use Rule Detector toggle switch.
  7. Enable or disable the function for skipping gaps in the incoming data stream using the Skip gaps in data toggle switch.
  8. In the Maximum number of records requested from the Message Broker service field, enter the number of records that must be requested from the Message Broker service for subsequent processing in the Anomaly Detector.
  9. In the Number of messages sent in one block to the Message Broker service field, enter the number of incidents that must be sent to the Message Broker service at one time.
  10. In the Number of simultaneously running models field, enter the maximum number of ML models that can analyze telemetry data at the same time.

    For maximum performance of Kaspersky MLAD, the number of ML models running at the same time must not exceed 80% of the number of cores of the server where Kaspersky MLAD is installed.

  11. Click the Save button.
Page top