Kaspersky Machine Learning for Anomaly Detection

Viewing the technical specifications of a registered incident

Expand all | Collapse all

The functionality is available after a license key is added.

In the Incidents section, you can view the technical specifications of registered incidents. To do so, click the A green closing angle bracket icon. button near the relevant incident in the incidents table. The following technical specifications will be displayed for the selected incident:

  • Incident is the section containing information about the incident.
  • Top tag is a section that contains information about the tag that had the greatest impact on incident registration.
  • Stream Processor service incident parameters is a section containing information about the parameters of the incident registered by the Stream Processor service. This group of parameters is displayed if the current incident is registered by the Stream Processor service.
  • Incident cause is the field for selecting the cause of the incident. This field is completed by an expert (process engineer or ICS specialist). If necessary, the system administrator can create, edit, or delete causes of incidents.

    An incident cause can be assigned automatically if a cause is specified in the parameters of the ML model element that registered the incident.

  • Expert opinion is the field for adding an expert opinion based on an analysis of the registered incident. This field is completed by an expert (process engineer or ICS specialist).

    An expert opinion can be assigned automatically if an opinion is specified in the parameters of the ML model element that registered the incident.

  • Note is the field for entering a comment for the selected incident. If necessary, you can provide a comment for the incident.