Custom thresholds
The Custom Thresholds page displays the threshold definitions and provides the option to create new threshold definitions. Only the threshold definitions for the selected host are displayed on the page.
To view a threshold's configuration from the Custom Thresholds page, select the + icon for a specific threshold. You can expand multiple threshold at a time.
- NAME: The name of the threshold definition.
- TYPE: The type of change that the threshold definition monitors.
- ENABLED: Indicates whether the threshold definition is enabled and be used by IBM® Storage Defender Sentinel anomaly scan software.
- LAST MODIFIED: Indicates the last time the threshold definition was modified.
- HOST: The host IP address or name that is monitored by the threshold definition.
- ACTIONS: The actions that can be taken on the threshold definition, which are edit and delete.
A custom threshold defines a threshold at a granular level, which gives you the maximum flexibility for configuring alert thresholds. You can create a custom threshold definition for the files and paths to monitor. In addition, you can define the type of changes to the files and set severity levels of the alerts. The files and directories typically monitored are important system files and folders that infrequently or never change. If the custom threshold definition for a change is exceeded between two snapshots, then an alert at the user-configured severity level is created immediately. The alerts are generated any time when a custom threshold is reached with every scan of a host.
You can view the graphs for custom threshold definitions for a host by navigating to. Each configured severity level is indicated on the graphs with by using a specific color dashed line. If you change the severity level values of the daily activity threshold, the lines move based on the new values you provided.
Alerts are generated when a custom threshold is exceeded with every scan of that host. This is different than the hosts threshold alerts, which only occur once in a 24-hour period.
The following options are available to configure threshold:
Creating a custom threshold
- On the page, click .
- The New Custom Threshold page appears. Toggle the Enable Alert Threshold to enable generating alerts when the daily activity limit has been reached. By default, the option is enabled.
- Add the following information on the New Custom Threshold page:
- Name: A user-defined name of the threshold configuration. You can use a name that describes the threshold type, such as "Deleted Files - 10 Percent - Finance Servers". It helps you to easily identify the exceeding threshold and the associated host.
- Type: Select one of the following options from the drop-down:
- Added Files: The number of added files that has occurred between the last two backups analyzed.
- Changed or Deleted: The number of files that have changed content or the files have been deleted since the last backup analyzed. This monitors a comprehensive change to the files or folders, combining deletions and file content changes.
- Changed File Type: The number of files in a previous backup that have a different file type in the current backup.
Note: When you configure a Daily Activity or custom threshold for Changed File Type, the threshold considers the Trusted and Unknown to be the same file type. However, a file of the unknown type that matches the filename pattern under , the file still appears as Trusted in the table.
- Deleted Files: The number of deleted files that has occurred between the last two backups analyzed.
- Entropy: The randomness of data in a file and generally indicates file encryption. Encrypting a file typically increases the entropy of the file. The entropy value ranges from 0 (no entropy) to 100 (maximum entropy).
- Data Format: The number of files affected by the change type as a percentage or quantity. Select Quantity or Percentage. For Entropy, only the Percentage option is available.
- Severity: Set a value for each severity level that you want to use. At least one severity level must be set. The value must decrease for each level, which are:
- Critical
- High
- Medium
- Low
A threshold exceeded alert is triggered when the number or percentage of changed files is greater than the value set for a severity level. For example, you created a custom threshold for a percent of deleted files and want to be alerted when more than 20%, 15%, 10%, and 5% of your files have been deleted. Set the severity levels as follows:- Critical to 20
- High to 15
- Medium to 10
- Low to 5
- Minimum: The option is only available for the Entropy change type. It configures the minimum entropy that the configured percentage of files must be for an alert to be generated. For example, if you have set Value to 20% and Minimum to 90, then more than 20% of the files must have an entropy of at least 90 to generate an alert.
- For the Add Location field, provide the following inform
- Host: The name or IP address of the host that you want to monitor for changes.
- Path: The path can be a directory or a path to a file. This is defined relative to the snapshot.
- Include Subdirectories: The threshold is applied to the host and path and any existing subdirectories to analyze the files for changes.
Note: For more information, see Hosts and paths. - Click Save Changes to save the configuration.
Editing a custom threshold
- On the , select the Edit icon under the ACTIONS column.
- The Edit Custom Threshold page appears. Toggle the Enable Alert Threshold to enable/disable generating alerts when the daily activity limit has been reached. If you want to delete the custom threshold, select Delete.
- Edit the information for the following fields:
- Name
- Type
- Data Format
- Severity
- Minimum
- . For a location , edit the following information:
- Host
- Path
- Include Subdirectories
- Select Add Location + to add more locations to the threshold.
- Click Save Changes to save the configuration.