Docs

Type at least 2 letters.

    Knowledge base

    Record your environment's context, such as allowed origins and maintenance windows, for the analysis agent to check when assessing spikes.

    Updated View as Markdown

    The knowledge base stores the context the analysis agent consults when assessing the tenant's spikes. An item can record, for example, that an IP belongs to a partner or that there was scheduled maintenance. The analysis takes that context into account.

    Before you start

    • To see the base, you need the responder.read permission. To create, edit or delete items, you need responder.knowledge.write. The Tenant Admin role has both. Tenant User has read-only access.
    • To understand where the context comes in, see AI analysis.

    Item types

    Type Use
    Origem permitida (Allowed origin) A traffic origin you recognize and accept.
    Robô conhecido (Known bot) A bot whose access is expected.
    Contexto de negócio (Business context) Information about the business that helps read the traffic.
    Janela de manutenção (Maintenance window) A scheduled maintenance period.
    Procedimento (Procedure) How your team handles a kind of case.
    Nota (Note) Any other context.

    Create an item

    1. Go to Administração (Administration) > Base de conhecimento (Knowledge base).

    2. Select Novo item (New item).

    3. Fill in the main fields:

      Field Limit
      Tipo (Type) One of the types in the table above.
      Título (Title) Up to 160 characters.
      Contexto (Context) Up to 4000 characters.
    4. (Optional) To limit the item to specific cases, fill in Quando se aplica (When it applies). See the section below.

    5. (Optional) To limit the item to a period, fill in the validity. See Validity.

    6. Keep Item ativo (o agente consulta este item) (Active item: the agent checks this item) selected.

    7. Select Criar item (Create item).

    To change an item, select Editar (Edit) and then Salvar (Save). To remove it, select Excluir (Delete).

    When it applies

    These fields limit the item to specific cases. Each list accepts up to 100 values.

    Field Compared with
    IPs e faixas (CIDR) (IPs and ranges) The case's source IP.
    ASNs The case's source ASN.
    Hosts The host accessed.
    Prefixos de path (Path prefixes) The start of the path accessed.
    Zonas (Zones) The case's zone.
    Tipos de regra (Rule types) The type of the detection rule that opened the case.
    • If you fill in more than one list, the case must match all filled lists.
    • With no list filled in, the item applies to every case.

    Validity

    Situation How to fill in
    Permanent item Leave Válido a partir de (Valid from) and Válido até (Valid until) blank. Without dates, the item always applies.
    Temporary item Fill in one or both dates.
    Janela de manutenção Início (Start) and Fim (End) are required.

    Item badges

    Badge What it means
    Em vigor (In effect) The item is active and within its validity. The agent checks it.
    Agendado (Scheduled) The start date has not arrived yet.
    Expirado (Expired) The end date has passed.
    Desativado (Disabled) Item ativo is cleared. The agent does not check it.
    Global Item maintained by Guardnet for all tenants. Read-only.