About incidents

An incident is an identified deviation from the expected (normal) behavior of a monitored asset.

Kaspersky MLAD supports incident registration for the following sources:

When a deviation is detected, the corresponding source records the date, time and relevant deviation parameters, and saves this data as an entry in the Incidents section. If incident notifications for users or external systems are created in Kaspersky MLAD, information about an incident is sent to the intended recipients via the corresponding services of Kaspersky MLAD.

In this section

About incidents detected by a predictive element of an ML model

About incidents detected by an ML model element based on a diagnostic rule

About incidents detected by an ML model element based on an elliptic envelope

About incidents detected by the Limit Detector

About incidents detected by the Stream Processor service

See also:

Working with incidents and groups of incidents

Page top