IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Work No Traffic Alert

    Posted Sun January 21, 2024 12:56 PM

    Hello everyone!
    I want to use No Traffic Alert. I studied the documentation, tried the work and still can't understand how it works.
    When setting up, it is recommended to change 3 parameters - accumulation interval, notification interval, run frequency.
    If I understand correctly, accumulation interval is an interval during which there should be no traffic. No Traffic Alert will work if there was traffic in the last 48 hours, but there was no traffic during the time specified in the accumulation interval. I don't understand why the notification interval, run frequency parameters are needed, if I want alerts to be created every time there is no traffic. What parameters do I need to set in notification interval, run frequency?

    I will be glad to receive any help.



    ------------------------------
    Yana Nkr
    ------------------------------


  • 2.  RE: Work No Traffic Alert

    Posted Mon January 22, 2024 08:46 AM

    Can you share a screenshot of your current configuration for the no traffic alert?

    It might be easier to help define what is not functioning.

    run frequency - is how often the alert check runs

    notification interval - is how often it will notify - so for example every hour 1 or every day 1440



    ------------------------------
    Ben M
    [
    ------------------------------



  • 3.  RE: Work No Traffic Alert

    Posted Mon January 22, 2024 09:01 AM
    My configuration


    ------------------------------
    Yana Nkr
    ------------------------------



  • 4.  RE: Work No Traffic Alert

    Posted Mon January 22, 2024 09:26 AM

    You need to enable the alert. Under the run frequency option there is the Active check mark. Make sure that is enabled. Also have you configured the Alerter?



    ------------------------------
    Ben M
    [
    ------------------------------



  • 5.  RE: Work No Traffic Alert

    Posted Mon January 22, 2024 09:39 AM

    It was on. Now turned off to change parameters.

    Am I understanding correctly, this will run every hour and check if there is any traffic in the last 15 minutes? If there was no traffic in the last 15 minutes, but there was traffic in the last 48 hours, will the alert be sent every hour until traffic is sent again?
    And if there is traffic in the last 15 minutes, but there was none 20 minutes ago, will this work?



    ------------------------------
    Yana Nkr
    ------------------------------



  • 6.  RE: Work No Traffic Alert

    Posted Mon January 22, 2024 09:50 AM

    Am I understanding correctly, this will run every hour and check if there is any traffic in the last 15 minutes?

    since you have the parameter set to 15 minutes - this should mean that no traffic for 15 minutes will generate an alert the next time the check runs which is hourly on your config. So it could generate 3-4 alerts if no traffic for 59-60 minutes.

    If there was no traffic in the last 15 minutes, but there was traffic in the last 48 hours, will the alert be sent every hour until traffic is sent again?

    Not sure where the 48 hours traffic comes in to play. Based on the configuration it should be no traffic for 15 minutes will create an event the next the alert is checked. It should summarize the alerts for the 60 minute time window, but I haven't set it where the Accumulation interval is lower than the alert Run frequency. 

    And if there is traffic in the last 15 minutes, but there was none 20 minutes ago, will this work? Based on my understanding if there is a 15 minute period of no traffic you should get an alert even if there was traffic after that before the alert run frequency triggered it is looking at data in a report not active data at that moment in time.



    ------------------------------
    Ben M
    ------------------------------



  • 7.  RE: Work No Traffic Alert

    Posted Mon January 22, 2024 09:54 AM

    To clarify: "The no traffic alert is mentioning that over a 48 hour window of monitoring that the alert parameters were met to alert. NO Traffic for 15 minutes in the 48 hour time frame. That would be any 15 minutes during that 48 hours."

    Do you have monitored servers (S-Taps)?

    Alert to indicate whether there is no traffic from specific database servers. This alert will alert when there is no traffic collected from a server from which the Guardium system was collecting traffic at some point during the last 48 hours. The alert will trigger when there is no traffic within the period defined in the accumulation interval.
    For example if the accumulation interval is 60 minutes the alert will send an email if there was no traffic from a specific database server in the last hour but there was some traffic in the last 48 hours.  The alert will send an email (by default) only every 24 hours. Parameters such as accumulation interval, notification interval, run frequency etc. can be customized. Parameters such as Threshold, Per Line, operator, query etc. should not be changed, as changes to these parameters will cause the alert not to work properly. 



    ------------------------------
    Ben M
    ------------------------------



  • 8.  RE: Work No Traffic Alert

    Posted Mon January 22, 2024 12:07 PM

    I got further clarification and it all lines up.

    Run Frequency - 60 minutes - how often it looks at the report data for no traffic

    accumulation interval - 15 minutes - amount of continuous time without traffic (inside the 48 hour period) example 1:00am to 1:16am no traffic valid alert condition

    notification period - how often the alert will be sent to the user(s) default once per 24 hour period. So even if the above condition is true it will only send out once per day. Example notification triggered at 9:00am on Tuesday the next possible time for a notification is after 9:00am on Wednesday.



    ------------------------------
    Ben M
    ------------------------------