Blocking Anomalies
Identify Nodes through Node Group and Block them through New Enforcement Policy
You may create a dedicated Node Group and an Enforcement Policy accordingly.
Create Anomaly Node Group
This will group together all Nodes that will be identified by the default Policy using enabled Anomaly Definitions.
Go to Policy in the top panel.
Go to Policy > Group > Node in the left Policy panel.
Click on Tasks > Create
For ID: Unique Name. (e.g. Anomaly Group)
For Status: Enabled.
For Boolean Operator select OR.
Find and click on Add in Condition section.
For each Anomaly you want to add, use the followings:
Options: Anomaly
Operator: Detected is one of
Value: (One of the listed Anomalies)
Click Add.
Keep adding Conditions as needed.
Click Save.
Create Enforcement Policy To Block Anomalies
This will block all Anomalies identified within the Node Policy and are listed in the Anomaly Group from Step 1.
Go to Policy in the top panel.
Go to Enforcement Policy in the left Policy panel.
Click on Tasks > Create.
Action tab, click Next.
Under General tab:
ID: Unique Name. (e.g. Anomaly Enforcement Policy)
Description: Anomaly Policy to block all Nodes detected as Anomalies.
Status: Enabled.
Click Next.
Node Group tab, find and double click ** Group** (e.g. Anomaly Group)
Permission tab, double click on PERM-DNS. Click Next.
Redirection tab, click Next.
Agent Action tab, click Finish.
Click Apply.