Getting Started with Intelligence Policy
An Intelligence policy has a ruleset (containing event definitions), one or more environments on which the events are applied, and a notification indicating where findings must be sent.
To set up an Intelligence policy:
-
Navigate to the Policies page in the CDR > Threat Monitoring menu.
-
Click Add Policy on the right.
-
Select a platform on which the policy applies and click Next.
-
Select one or more environments to which the policy applies. CloudGuard shows only those environments onboarded to Intelligence. Click Next.
-
For the initial Intelligence configuration, use the configured CloudGuard-managed rulesets. From the list, select one or more rulesets for the policy and click Next.
-
To add a new Notification, click Add Notification.
-
In the Create New Notification window, enter the notification name and, optionally, a description. For this initial policy, you can use the default settings. Make sure that the Alert console is selected. This option allows you to see all findings on the Events > Threat & Security Events page.
-
Click Save.
-
Select the Notification for the association.
-
Click Save.
Your policy appears on the Policies page.
More Links