I have successfully created an anomaly detection rule to help monitor the amount of traffic to a website and is alerting when the volume increased by x%. For an automated response, it would be helpful to know what the anomaly detection rule was currently using for the average it was basing the rule off of. I tried digging through the reference sets/maps/tables but could not find anything.
Is there a place I can go to find what the rule is currently using for the is average to know when to trigger the rule?
#QRadar#Support#SupportMigration