Kaspersky Machine Learning for Anomaly Detection

Creating a monitor

December 6, 2023

ID 248084

Monitor management is available to system administrators.

To create a monitor:

  1. In the main menu, select the Event Processor → Monitoring section.
  2. Click the Create monitor button.

    The Create monitor pane appears on the right.

  3. Specify the monitor name in the Name field.
  4. In the Sliding window (sec.) field, specify the interval (in seconds) from the current point in time back to the time sequence for which the monitor will process incoming values of parameters, events or patterns.
  5. In the Threshold field, specify the number of monitor activations in the sliding window after which the monitor sends an alert to the external system.
  6. In the Stack limit field, specify the number of monitor activations that must be displayed when viewing information about the monitor.
  7. In the Subscription type drop-down list, select one of the following values:
    • If you need to process data on the values of event parameters, select Parameter values.
    • If you need to process data on events, select Events.
    • If you need to process data on detected patterns, select Patterns.
  8. If you need to track new events, patterns, or values of event parameters, turn on the Only new toggle switch in the Filters section.
  9. To focus the attention of the model on specific directions of events, do one of the following:
    • If you selected Events from the Subscription type drop-down list, select Attention for the relevant event parameter. If you need to track events without specifying the attention direction, clear the Attention check box.
    • If you selected Patterns from the Subscription type drop-down list, select the Attention check box for the relevant event parameter.

    You can select only one attention direction.

  10. For each event parameter, do one of the following:
    • If you need to process data on all values of an event parameter, use the drop-down list to select All parameter values.

      This option is displayed if you specified the attention direction for the current event parameter.

    • To process data only on the new values of an event parameter, in the drop-down list select New parameter values.

      This option is displayed only when the Only new function is enabled for event-based data processing.

    • To process data for a specific value of an event parameter, in the drop-down list select the event parameter value. As you start typing a value, all matching parameter values are displayed in the list.

      If the parameter value is not listed, enter the required value and select Create Value: <event parameter value>.

    • If you need to process data based on an event parameter value template, turn on the Regular expression toggle switch for the relevant event parameter, use the drop-down list to enter the value template with a regular expression, and select Regular expression: <value template>.

      You can use special characters of regular expressions to search patterns using regular expressions.

  11. Click the Create button.

The new monitor is created and displayed on the Monitoring tab.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.