Blocking Anomalies
Identify Nodes through Node Group and Block them through New Enforcement Policy
You may create a dedicated Node Group and an Enforcement Policy accordingly.
Create Anomaly Node Group
This will group together all Nodes that will be identified by the default Policy using enabled Anomaly Definitions.
- Go to Policy in the top panel.
- Go to Policy > Group > Node in the left Policy panel.
- Click on Tasks > Create
- For ID: Unique Name. (e.g. Anomaly Group)
- For Status: Enabled.
- For Boolean Operator select OR.
- Find and click on Add in Condition section.
- For each Anomaly you want to add, use the followings:
- Options: Anomaly
- Operator: Detected is one of
- Value: (One of the listed Anomalies)
- Click Add.
- Keep adding Conditions as needed.
- Click Save.
Create Enforcement Policy To Block Anomalies
This will block all Anomalies identified within the Node Policy and are listed in the Anomaly Group from Step 1.
- Go to Policy in the top panel.
- Go to Enforcement Policy in the left Policy panel.
- Click on Tasks > Create.
- Action tab, click Next.
- Under General tab:
- ID: Unique Name. (e.g. Anomaly Enforcement Policy)
- Description: Anomaly Policy to block all Nodes detected as Anomalies.
- Status: Enabled.
- Click Next.
- Node Group tab, find and double click ** Group** (e.g. Anomaly Group)
- Permission tab, double click on PERM-DNS. Click Next.
- Redirection tab, click Next.
- Agent Action tab, click Finish.
- Click Apply.