Enabling Anomaly Detection using Sigma Rules
To enable Anomaly Detection using Sigma rules:
- In the main window of the Web Console, select Assets (Devices) → Policies & profiles.
- Click the name of the Kaspersky Industrial CyberSecurity for Nodes policy.
The policy properties window opens.
- Select the Application settings tab.
- In the Anomaly Detection using Sigma rules section, select the Enable Anomaly Detection using Sigma rules check box.
- Add one or more collections of Sigma rules.
- Click the Save button.
Kaspersky Industrial CyberSecurity for Nodes will search for anomalies using the enabled collections of Sigma rules.
Page top