Knowledge base
Record your environment's context, such as allowed origins and maintenance windows, for the analysis agent to check when assessing spikes.
The knowledge base stores the context the analysis agent consults when assessing the tenant's spikes. An item can record, for example, that an IP belongs to a partner or that there was scheduled maintenance. The analysis takes that context into account.
Before you start
- To see the base, you need the
responder.readpermission. To create, edit or delete items, you needresponder.knowledge.write. The Tenant Admin role has both. Tenant User has read-only access. - To understand where the context comes in, see AI analysis.
Item types
| Type | Use |
|---|---|
| Origem permitida (Allowed origin) | A traffic origin you recognize and accept. |
| Robô conhecido (Known bot) | A bot whose access is expected. |
| Contexto de negócio (Business context) | Information about the business that helps read the traffic. |
| Janela de manutenção (Maintenance window) | A scheduled maintenance period. |
| Procedimento (Procedure) | How your team handles a kind of case. |
| Nota (Note) | Any other context. |
Create an item
-
Go to Administração (Administration) > Base de conhecimento (Knowledge base).
-
Select Novo item (New item).
-
Fill in the main fields:
Field Limit Tipo (Type) One of the types in the table above. Título (Title) Up to 160 characters. Contexto (Context) Up to 4000 characters. -
(Optional) To limit the item to specific cases, fill in Quando se aplica (When it applies). See the section below.
-
(Optional) To limit the item to a period, fill in the validity. See Validity.
-
Keep Item ativo (o agente consulta este item) (Active item: the agent checks this item) selected.
-
Select Criar item (Create item).
To change an item, select Editar (Edit) and then Salvar (Save). To remove it, select Excluir (Delete).
When it applies
These fields limit the item to specific cases. Each list accepts up to 100 values.
| Field | Compared with |
|---|---|
| IPs e faixas (CIDR) (IPs and ranges) | The case's source IP. |
| ASNs | The case's source ASN. |
| Hosts | The host accessed. |
| Prefixos de path (Path prefixes) | The start of the path accessed. |
| Zonas (Zones) | The case's zone. |
| Tipos de regra (Rule types) | The type of the detection rule that opened the case. |
- If you fill in more than one list, the case must match all filled lists.
- With no list filled in, the item applies to every case.
Validity
| Situation | How to fill in |
|---|---|
| Permanent item | Leave Válido a partir de (Valid from) and Válido até (Valid until) blank. Without dates, the item always applies. |
| Temporary item | Fill in one or both dates. |
| Janela de manutenção | Início (Start) and Fim (End) are required. |
Item badges
| Badge | What it means |
|---|---|
| Em vigor (In effect) | The item is active and within its validity. The agent checks it. |
| Agendado (Scheduled) | The start date has not arrived yet. |
| Expirado (Expired) | The end date has passed. |
| Desativado (Disabled) | Item ativo is cleared. The agent does not check it. |
| Global | Item maintained by Guardnet for all tenants. Read-only. |