Checking the AI Settings
Last updated
Last updated
The AI module works with parameters and users can edit the parameters under the "Settings & Reporting" -> "AI Questions" -> "AI Analysis Auto Exclusion Settings". The default parameters should be like this:
Classify, Enrich & Auto-whitelist for Windows processes
ON
Classify, Enrich & Auto-exclude on Sysmon for Windows processes
ON
Minimum Count Threshold for Auto AI Analysis Exclusions
100
Minimum Elastic Count Threshold for Auto AI Analysis Exclusions
Optional: 0=disabled, default=20
Auto AI Analysis Exclusions Run Interval
24
Auto AI Analysis Exclusions Last Execution
It will change automaticly on each iteration.
Make sure to click on the "Save" button before activating the AI auto-exclusions. If it is not saved, the AI module is not working properly.