ENGINSIGHT
WebsiteLoginKostenloser Testzugang
English
English
  • Overview
  • Features
  • Operation
    • Platform overview
    • Start Guide
    • Platform
      • Dashboard
        • Vulnerability Management
        • Operation Centers
        • My Dashboards
        • Configurations
      • Issues
      • Hosts (Pulsar Agent)
        • Pulsar Agent
        • Host details
        • Policy Manager
        • Software Inventory
        • Intrusion Detection System
        • File Integrity Monitoring
        • System events
        • Update Manager
        • Plugins
        • Machine Learning
      • Host (Pulsar-Agent) BETA
        • Pulsar Agent
        • Hostdetails
        • Softwareinventar
        • Plugins
        • Policies
        • Globale Tags
        • Tag Manager
        • System Events
        • Vulnerability Manager
        • Compliance
        • Intrusion Detection System
        • File Integrity Monitoring
        • Advanced Persistent Threats
      • Endpoints (Observer)
        • Endpoint details
        • Domains
        • Certificate Manager
        • Observer
      • Observations
      • Shield
      • Penetration Testing (Hacktor)
        • Run pentest
        • Audits
        • Audit Definitions
        • Target Groups
        • Auth-Providers
        • Hacktor
        • Custom Scripts
      • Discoveries
      • SIEM
        • Data Lake
        • Cockpits
        • Obfuscators
        • Workflows
        • Incidents
        • Extractors
        • Collectors
        • Loggernaut
        • Advanced Settings
        • Models
      • Alerts
      • Settings
      • Organisations
      • Tags
      • Searchbar
  • On-Premises
    • Requirements
    • Installation
      • Automatic Installation
      • Manual Installation
      • Load Balancing
      • SIEM
      • Deinstallation
    • Update
    • Configuration
      • HTTPS and Certificates
      • Licences and Organisations
      • Mail Server
      • 2-Factor Authentication
      • SSO via Office 365
      • Storage Times
      • White Label
      • NGINX Extractor
      • Field Level Encryption
      • Loggernaut-Configurations
  • Technical Details
    • System Requirements
      • Pulsar: Operating Systems
    • Current version numbers
    • Pentest Vectors
    • API
  • Partner section
    • Licenses and organizations
Powered by GitBook
On this page
  • Metrics
  • Switch alert to anomalies

Was this helpful?

  1. Operation
  2. Platform
  3. Hosts (Pulsar Agent)

Machine Learning

PreviousPluginsNextHost (Pulsar-Agent) BETA

Last updated 1 year ago

Was this helpful?

The Machine Learning module is capable of analyzing and understanding the data progression and predicting normal operation. In case of unusual processes it categorizes the deviation as low, medium or high and triggers an alarm if desired.

Metrics

Define which metrics you want to monitor with Machine Learning. You can either assign the monitoring to individual server metrics or you can use . We recommend the latter. With tags, you can have a large number of server metrics permanently and autonomously checked for anomalies with just a few clicks.

The best way is to create a separate tag for monitoring by Machine Learning and assign it to all servers whose metrics you want to monitor.

To set up monitoring, follow these steps:

  1. Click on "+ Metrics".

  2. Enter a description.

  3. Under "Assigned references", specify which hosts you want to monitor. Select either a single host ("Exclusive") or multiple hosts via tags ("All with the tags").

  4. Under "Metrics", select which metrics you want to monitor.

  5. Click on "Save Changes". Enginsight immediately begins calculating a normal metric history.

For the Machine Learning module to create a profile for a metric, valid metric data must be available over a period of 48 hours. You can set up ML monitoring before this time, but you will only be notified that the profile is still being calculated.

Switch alert to anomalies

To be notified of anomalies, you can create an alarm.

  1. For reference, select either a single host or the Machine Learning tag you created. This allows you to set an alert on all metrics at once.

  2. Select the condition "Machine Learning: Unusual behavior".

  3. Specify who should be notified.

  4. Save the alert.

The alarm is only resolved if the Machine Learning module classifies the deviation as "high".

In addition to monitoring the standard metrics collected by Enginsight (CPU, RAM, hard drives, network, etc.), you can also monitor your own defined using the Machine Learning module. For example, you can use Enginsight to detect anomalies in database behavior.

To do so, go to the Alerts module and .

tags
create a new alert
custom metrics