Quickly Adding a Log Alarm Model
SecMaster allows you to set alarm models for query and analysis results and trigger alarms when conditions are met.
This topic describes how to quickly configure alarm models for logs.
Prerequisites
Data access has been completed. For details, see Data Integration.
Procedure
- Log in to the management console.
- Click in the upper left corner of the page and choose .
- In the navigation pane, choose Workspaces > Management. In the workspace list, click the name of the target workspace.
Figure 1 Management
- In the navigation pane on the left, choose
. The security analysis page is displayed.Figure 2 Accessing the Security Analysis tab page
- In the data space navigation tree on the left, click a data space name to show the pipeline list. Click a pipeline name. On the displayed page, you can search the pipeline data.
Figure 3 Pipeline data page
- Enter the query analysis statement, set the time range, and click Query/Analyze. The query analysis result is displayed.
For details, see Querying and Analyzing Data.
- Click Add Alarm in the upper right corner of the page. The Create Alarm Model page is displayed.
Figure 4 Add Alarm
- Configure basic alarm information by referring to Table 1.
Figure 5 Basic configuration
Table 1 Basic parameters of an alarm model Parameter
Description
Pipeline Name
The pipeline where the alert model is executed, which is generated by the system by default.
Model Name
Name of the alarm model.
Severity
Severity of alarms reported by the alarm model. You can set the severity to Critical, High, Medium Low, or Informative.
Alarm Type
Alarm type displayed after the alarm model is triggered.
Model Type
The default value is Rule model.
Description
Enter the description of the alarm model.
Status
The alarm model status.
- : indicates that the model is enabled. This is the default status.
- : indicates that the model is disabled.
You can change the alarm model status after the model is configured.
- After the setting is complete, click Next in the lower right corner of the page. The page for setting the model logic is displayed.
- Set the model logic. For details about the parameters, see Table 2.
- After the setting is complete, click Next in the lower right corner of the page. The model details preview page is displayed.
- After confirming that the preview is correct, click OK in the lower right corner of the page to confirm the configuration.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot