You can create multiple attention heads and use different attention heads for different monitors simultaneously.
The functionality is available after a license key is added.
A large number of attention heads can lead to reduced event processor performance and slow down the core Kaspersky MLAD services, such as data reception, anomaly detection, and the web interface. To clarify the number of attention heads, it is recommended to consult with Kaspersky experts or a certified integrator.
To add an attention head:
The Attention heads panel appears on the right.
The Add attention head panel appears on the right.
When this attention type is selected, the event processor will register generic patterns that will not display the selected event parameter with the selected value when viewed. The Event Processor will track each specified event parameter value separately.
Selecting All values causes the event processor to track events and patterns for each specific event parameter value separately. To ensure stable event processor performance, we recommend defining specific values for the event subject.
If you selected Generalized attention as the attention type, select at least two values for the event parameter.
You can use special characters of regular expressions to search for events and patterns based on regular expressions.
If generalized attention was selected as the attention type, then, when the switch is on, the event processor will generalize the remaining event parameters across all their values. In this case, the event processor will not register any event or pattern. To enable the Event Processor to generate events or patterns, you must define at least one event parameter in the Conditions block without generalization based on its values.
When this condition type is selected, the event processor will register patterns that, when viewed, will not display the selected event parameter with the selected value.
This value is available if the Generalized attention type is selected for the attention subject.
New values is available in the following cases:
All values is available in the following cases:
You can use special characters of regular expressions to search for events and patterns based on regular expressions.
You can set more than one condition for additional event parameters. You can delete a previously added condition by clicking next to the condition.
The conditions will be additionally applied to the data sample obtained for the main event parameter set under Attention subject. For example, if the Generalized attention type is selected and the Generalize condition parameters toggle switch is on, the Event Processor will register patterns that will display only those event parameters that were specified under Conditions while considering their selected values. If the toggle switch is off, the event processor will register patterns that will not display the generalized parameter specified under Attention subject. In this case, the values of the event parameters specified under Conditions will be considered.
Information about the new attention head will be displayed in the table, in the Attention heads panel. You can rename the attention head, and enable or disable the use of the attention head for event processing.
Page top