Threat management is a core capability of the high availability (HA) management platform. It aggregates threats and alerts from monitoring and inspections, and serves as a centralized platform to collect, handle, and manage threat events to completion.
The Threat Events page displays all threat events in the current environment and their summary information, including threat name, threat status, object type, and summary.
If threat events in the list are not handled promptly, many duplicate, low-level threats can be generated. The Threat Management module can aggregate identical threat events, which you can then handle individually or in a batch.
Create a threat event
Log on to the high availability (HA) management console.
In the navigation pane on the left, click Risk Management > Threat Events.
Click Create Threat Event. In the Create Threat Event panel, configure the following parameters:
Parameter
Required
Description
Threat Name
Required
A custom name for the threat.
Risk Level
Required
Specifies the risk level for management and monitoring purposes. The available levels are High, Medium, and Low.
Description
This parameter is required.
A custom description for the threat.
Object Type
Required
You can select User Application, or Other.
Object Name
Required
Select or enter the object name.
Click Confirm.
Handle a threat event
Without an associated threat scenario
If a threat event is not associated with a threat scenario, no data is available for emergency analysis or plan recommendations.
Procedure
In the left navigation pane, click Risk Management > Risk Events.
Find a threat with the Pending status. In the Operation column, click Handle to open the threat details page.
Handle the threat event as follows:
On the Emergency Procedure tab, click Add Emergency Step. The threat status changes to In Progress.
On the Emergency Response tab, click Respond Now. The threat status changes to In Progress.
After you handle the threat, click Complete Emergency on the threat event details page. This completes the process and changes the threat event status to Closed.
Associated threat scenarios
You can manually associate a threat event with a threat scenario. This action does not trigger a diagnostic execution. Instead, the Threat Management module recommends emergency plans that you can execute manually.
Procedure
In the left navigation pane, click Risk Management > Threat Events.
Find a threat with the Pending status. In the Operation column, click
> Associate Threat Scenario.Select a threat scenario. To create a new one, see Create a threat scenario.
Find a threat with the Pending status. In the Operation column, click Handle to open the threat details page.
Handle the threat event as follows:
On the Emergency Response tab, click Respond Now. The threat status changes to In Progress.
On the Emergency Procedure tab, click Add Emergency Step. The threat status changes to In Progress.
On the Plan Recommendation tab, click a plan to execute it. The threat status changes to In Progress.
After you handle the threat, click Complete Emergency on the threat event details page. This completes the process and changes the threat event status to Closed.
View threat event details
The threat event details page displays basic information, threat information, execution objects, runtime parameters, execution details, and execution logs for the threat event.
Procedure
In the navigation pane on the left, click Threat Management > Threat Events.
Find the target threat event. In the Operation column, click Handle or View to see the details of the aggregated threat:
Risk Scenario Information: Risk Name, Object Type, Event Source, Risk Level, Number of Detections, Associated Risk Scenarios, First Detection Time, Last Detection Time, Summary, Emergency Response Time, Emergency Completion Time, and Risk Event Details.
Alert metrics
Emergency analysis: If the threat event is associated with a diagnostic decision tree, this section displays information about diagnostic anomalies detected by the automatically triggered decision tree.
Emergency response: Includes members who have and have not responded.
Emergency procedure: Shows the flow and progress of the current threat handling (Threat Discovered > Emergency Procedure > Emergency Complete) and the handling records.
Plan recommendation: If the threat event is associated with an emergency plan, this section displays recommended emergency plans based on the diagnosis and lets you execute them quickly.
You can also expand a threat event and click Details in the Operation column to view the details of a single threat event.
Close threat events in a batch
The HA management platform lets you close multiple threat events in a batch.
Procedure
In the navigation pane on the left, click Risk Management > Threat Events.
Select the threat events that you want to close, and then click Batch Close Threat Events.