Skip to main content
This section provides the purpose, elements, and actions performed on the Anomaly Detection pages.

Purpose

The Anomaly Detection page provides real-time visibility into unusual patterns, deviations, and potential security threats across cloud environments. It leverages advanced anomaly detection algorithms and integrates IDS/IPS capabilities for proactive monitoring and operational resilience. The Anomaly Detection page monitors selected VPC/VNets for unusual behavioral patterns in network traffic. CoPilot learns baseline traffic behavior over a configurable learning period, then raises anomalies when metrics deviate significantly from that baseline. Anomalies are categorized by severity (Low, Medium, or High) and can trigger alerts to configured notification channels.

Elements

Security: Anomaly Detection
  • Configuration — set the monitored VPC/VNets, detection sensitivity, and alert settings. - Dashboard — view anomaly data for the selected time range. The dashboard appears only after at least one monitored VPC/VNet completes its learning period. - Monitored VPC/VNets: Shows the count of VPC/VNets currently configured for anomaly detection. - Edit icon: Opens the Manage Monitored VPC/VNets dialog to add or remove VPC/VNets and configure the learning period. - List icon: Opens the Learning Status dialog to review the learning and detection status of each VPC/VNet. - X in Learning Phase chip: Appears when X number of VPC/VNets are still in the learning phase. Click the chip to open the Learning Status dialog. - Alerts toggle: Enables or disables anomaly alert notifications. Turning on the toggle opens a channel selection dialog. - Detection Sensitivity slider: Sets how aggressively CoPilot flags deviations. Marks: Low (1), Recommended (3), High (5).
  • Save button: Saves the configuration. Disabled when there are no pending changes. An Unsaved Changes chip appears when unsaved changes are present. - Date range picker: Filters the dashboard by time period. Options: Last 60 Minutes, Last 24 Hours, Last 7 Days (default), Last 30 Days. - Total Anomalies card: Total anomaly count for the selected period. - VPC/VNets with Anomalies card: Number of VPC/VNets that had at least one anomaly. - Metrics causing Anomalies card: Number of distinct traffic metrics that triggered anomalies. - Anomalies by Severity chart: Donut chart showing anomaly counts at Low, Medium, and High severity. - Anomalies by VPC/VNet chart: Donut chart showing anomaly counts per VPC/VNet. - Anomalies by Top Metric chart: Donut chart showing which traffic metrics triggered the most anomalies. - Anomalies Over Time chart: Line chart showing anomaly counts over the selected period. - Total Anomalies (Cumulative) chart: Line chart showing the running total of anomalies over the selected period. - Anomaly table: Lists all anomaly events in the selected time range.

Actions

Before viewing anomalies, ensure at least one monitored VPC/VNet has completed its learning period.To view anomalies:
  1. Go to Security > Anomaly Detection.
  2. Set the time range using the date range picker.
  3. Clic Apply.
  4. Review the summary cards.
  5. Inspect the charts.
  6. Investigate individual anomalies.
  7. Optionally, mark false positives by toggling the Anomaly switch for any row.
The anomaly table lists all anomaly events in the selected time range.
Before configuring anomaly detection, ensure you have all_write or all_security_write permissions in CoPilot.To configure anomaly detection:
  1. Go to Security > Anomaly Detection.
  2. In the Configuration section, click the edit icon next to Monitored VPC/VNets.
    The Manage Monitored VPC/VNets dialog appears.
  3. In the Manage Monitored VPC/VNets dialog, move VPC/VNets to the Monitored list.
  4. Set the Learning Period (in weeks; minimum 2, maximum 52).
  5. Click Save.
  6. Adjust the Detection Sensitivity slider to Low, Recommended, or High based on your environment’s tolerance for alert volume.
  7. Turn on the Alerts toggle. Select the notification channels in the dialog that appears.
  8. Click Save.
The number of monitored VPC/VNets updates with the new number of VPC/VNets configured for anomaly detection.
VPC/VNets in the learning phase do not produce anomaly data. The dashboard becomes visible only after the learning period ends for at least one monitored VPC/VNet. View learning status for each VPC/VNet by clicking thelist icon next to Monitored VPC/VNets.
To check learning status:
  1. Go to Security > Anomaly Detection.
  2. In the Configuration section, click the list icon next to Monitored VPC/VNets.
    The Learning Status dialog appears.
  3. Review the learning and detection status of each VPC/VNet.
The learning status dialog shows the learning start time, learning end time, and detection status (Active or Pending) for each VPC/VNet.
Detection for a VPC/VNet becomes Active after its learning end time passes. VPC/VNets still in the learning phase show Pending with the expected completion date.