These (below) are the default conditions which i see when i click on "Behavioral rule" while creating rule. However, i see some terms which i don't really understand such as "current traffic level", "current traffic trend" and "current traffic behavior". Can someone help explain to me on these?
and when this accumulated property is the tested property
and when the importance of the current traffic level (on a scale of 0 to 100) is 70 compared to learned traffic trends and behavior
and when the importance of the current traffic trend (on a scale of 0 to 100) is 30 compared to learned traffic levels and behavior
and when the importance of the current traffic behavior (on a scale of 0 to 100) is 30 compared to learned traffic levels and trends
and when the actual field value deviates by a margin of at least 50% of the extrapolated (predicted) field value
and when the season length is a day
Looking at the guide (below) with a given example on behavior rule, i could not really relate the example back to the conditions above:
Need help from the experts here to help me to understand on how Behavior rule works, as we are currently looking at one use case to track suspicious user activity on database based on SELECT query.
Appreciate any inputs here! Thanks!