IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only

Anomaly detection rules logic

  • 1.  Anomaly detection rules logic

    Posted 04/07/20 10:58 AM
    The following rule seems to be right in logic but is not triggering when there is a 40+% decrease in the number of events for a particular log source. How could I go about troubleshooting this rule?

    Apply [Anomaly - Outage] Possible system outage (Anomaly) when time series data is being aggregated by LogSourceType, EPS
    and when the average value (per interval) of SUM(EventCount) over the last 30 mins is at least 40% different from the average value (per interval) of the same property over the last 2 hours

    ------------------------------
    Vinnesh Rajaram
    ------------------------------