Skip to main content

Enable Security Analytics

This document provides instructions on enabling the Advanced Analytics Security Module (ASAM) in ObserveOps (formerly known as AIOps) Flow Explorer and customizing various elements of the Security Analytics feature.

How to enable the Security module

  1. Navigate to Settings > MOTADATA_NETFLOW > Security Analytics
  2. Click on "Enable" to enable the Security module
note

Make sure you have purchased the license for the Security module.

How to customize problem events

  1. Navigate to Settings > MOTADATA_NETFLOW > Security Analytics
  2. Click on "Manage Problems"
  3. Select any problem type and its sub-category
  4. Disable unwanted problem names under that class

How to customize resources

  1. Navigate to Settings > MOTADATA_NETFLOW > Security Analytics
  2. Click on "Manage Resource"
  3. Select RIP/IP/NET and choose the resources
  4. Disable unwanted resources
  5. To enable a particular resource, click on "Disable List" and follow the same procedure

How to customize ASAM algorithm

  1. Navigate to Settings > MOTADATA_NETFLOW > Security Analytics
  2. Click on "Manage Algorithm"
  3. Select any algorithm type and its sub-category
  4. Disable unwanted categorization for problems under that class

How to customize the threshold for events

ASAM has predefined thresholds for every problem class and its classification. You can edit thresholds for each problem type from Settings.

  1. Navigate to Settings > MOTADATA_NETFLOW > Attacks
  2. Click on "Threshold" to edit Threshold settings
  3. Click on any particular problem and edit the upper limit and lower threshold value
  4. Click on Advanced Settings for more changes
  5. Save

How to create an alert profile for ASAM

You can generate alerts and get notified in case of any threshold violation for attacks.

  1. Navigate to Settings > MOTADATA_NETFLOW > Security Analytics
  2. Click on "Alert Profiles" to edit or add a new alert notification
  3. Select Algorithm
  4. Provide Criteria
  5. Add the profile with a name, retention period, and notification details.
  6. Save