Managing Active Defense on Datasets

The Hub Active Defense → Active Protection page allows viewing and managing the protection and excessive file access settings of all datasets. Predefined filters exist for the administrator’s convenience to sort the list of datasets based on enabled properties.

Predefined filters include:

  1. Datasets - A summary of all the non-system datasets with the ability to manage and view each Dataset’s Active Defense and Excessive File Access status.

  2. Trials - Blocks Disabled - Displays only datasets with the Trial status.

    A dataset with a Trials status will indicates that the threats will only be reported and nothing will be blocked.
  3. Temporarily Disabled - Displays only datasets with the Temporarily Disabled status.

    A dataset with a Temporarily Disabled indicates threat detection is disabled until the defined time has passed.

To temporary disable Active Defense or enable Trials mode for a dataset, follow the steps below:

  1. Navigate to the Active Protection - Datasets page.

  2. Click the action cog cog icon next to the desired dataset.

  3. Navigate to the Active DefenseActive Protection page.

  4. Select the Datasets page.

  5. Click the Action Button on the desired Dataset.

  6. Select Edit Security.

  7. Toggle the desired features.

    1. Temporarily Suspend Blocks enables Active Defense protection only reporting detected issue without blocking user or host access.

    2. Temporarily Suspend Blocks and UB Collection temporary disables Active Defense protection and user behaviour detection. This is typically used during data migrations to prevent false notification and blocking from occurring.

  8. Apply changes to confirm.