IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Outlier Detection

  • 1.  Outlier Detection

    Posted Tue May 26, 2020 12:31 PM
    Hi all,

    Anyone with Guardium Outlier Detection experience that can share here with us?
    Is this really works?  What were the problems detected during the implementation?

    Thanks,
    Rodrigo

    ------------------------------
    Rodrigo Xavier
    ------------------------------


  • 2.  RE: Outlier Detection

    Posted Mon June 15, 2020 12:28 AM
    Hi,

    Yes, it is in use by many customers.
    I am not allowed to share examples of findings.
    It is in use to review and investigate the findings, in most cases the findings are distributed among people (using the Audit Process) and customers are using the "User Feedback" to eliminate data-element from future analysis. I.e., remove Objects (tables) like Temporary Objects that cause "white noise" (usually by wildcard), likewise to eliminate servers and/or users.
    The best practice is to have Audit Process in place for the outcome and assign automatically to people to review and investigate.


    ------------------------------
    ODED SOFER
    ------------------------------



  • 3.  RE: Outlier Detection

    Posted Mon June 15, 2020 04:11 PM
    Hi Oded,

    Thanks for your answer.
    But did you have some problems to enable and to start to receive events in outlier?  Something that you can remember and share?
    Everything you did to enable the outlier works immediatly?

    Thanks again,
    Rodrigo Xavier

    ------------------------------
    Rodrigo Xavier
    ------------------------------



  • 4.  RE: Outlier Detection

    Posted Tue June 16, 2020 03:51 AM
    Hello
    There is a document that explains how to enable and how to troubleshoot.
    If you need help with specific case, let me know and I will assign someone to work with you. 
    I will be glad to help

    ------------------------------
    ODED SOFER
    ------------------------------



  • 5.  RE: Outlier Detection

    Posted Tue June 16, 2020 08:18 AM
    Hi Oded,

    Can you share this document?

    Regards,
    Rodrigo Xavier

    ------------------------------
    Rodrigo Xavier
    ------------------------------



  • 6.  RE: Outlier Detection

    Posted Wed June 17, 2020 04:29 AM
    Hi Rodrigo

    See outlier detection in the knowledge center. It describes enabling and fine tuning outlier detection, and an overview of outliers in the investigation dashboard.

    Jill

    ------------------------------
    JILL GOLDBERG
    ------------------------------



  • 7.  RE: Outlier Detection

    Posted Wed June 17, 2020 07:48 AM
    Hi Jill,

    Thank you!

    Regards,
    Rodrigo

    ------------------------------
    Rodrigo Xavier
    ------------------------------



  • 8.  RE: Outlier Detection

    Posted Mon June 22, 2020 06:11 AM
    Hi Rodrigo,

    Please let me know if you need further assistance enabling outliers, configuring or understanding the results.

    Regards,
    Miri Levy
    Guardium


    ------------------------------
    MIRI LEVY
    ------------------------------



  • 9.  RE: Outlier Detection

    Posted Mon June 22, 2020 10:30 AM
    Hi Levy,

    Thank you.  I´ll let you know if a need further assistance.

    Best regards,
    Rodrigo Xavier

    ------------------------------
    Rodrigo Xavier
    ------------------------------



  • 10.  RE: Outlier Detection

    Posted Tue August 30, 2022 02:38 PM
    Hi Levy,

    It makes a long time about this topic here.  But the questions still remains...;-).
    All components about quick search, outlier and threat analysis is already enabled in the customer Guardium architecture.  But the customer wants to see an outlier event triggered.  They didn´t see anyone until now.  They´ve tried testing send some commands against the database as creating a new table and accessing it.  According to the customer, these activities never were done before.  But no outlier event was triggered.  How is the best simulation/test that you can suggest to do against the monitored database to trigger an outlier accurately?

    Regards,
    Rodrigo


    ------------------------------
    Rodrigo Xavier
    ------------------------------



  • 11.  RE: Outlier Detection

    Posted Mon May 17, 2021 01:06 PM
    Hi @ODED SOFER ,

    I have a problem with 'Analytic User Feedback'.

    I want to change some columns because the original report is insufficient for me.

    So I make a copy:

    And even without making any changes compared to the original.....

    ​....I always have this error:




    Why? Can you help me please?

    paolo (italy)


    ------------------------------
    Paolo Guerra
    ------------------------------



  • 12.  RE: Outlier Detection

    Posted Tue May 18, 2021 04:58 AM
    Hi @Paulo Cesar Guerra Braga
    There seems to be a bug in the metadata of that specific report.
    I am investigating it
    Please open a support case and ask that it is escalated to me.



    ------------------------------
    GUY GALIL
    ------------------------------