Anomaly Detection
The Anomaly Detection dashboard continuously identifies and prioritizes unusual behavior across monitored resources and applications. Security teams can view detected anomalies by application and filter or analyze them across different behavioral categories, such as new cross-application or geographic communication, risky traffic volumes, and external data transfers.
Detected anomalies are presented in a centralized table that provides key context at a glance, including the affected resource, anomaly category, anomaly strength or severity, and the time the anomaly was first detected. For each anomaly rule, the dashboard also shows the 30-day baseline behavior, along with the percentage deviation and the deviated value from the baseline, enabling security teams to quickly compare current behavior against what is expected.
For a more detailed investigation, security teams can view a historical visual representation of the behavioral pattern, including the established baseline, observed activity, and the points in time when an anomaly was triggered. This view highlights instances where behavior crosses the configured thresholds, helping teams understand the nature, frequency, and magnitude of the deviation over time. Each anomaly is also tracked through its investigation lifecycle with a status of New, Investigating, or Resolved, and teams can select View Details to examine the anomaly and its supporting evidence in greater depth.