Alerts
Important
This documentation is for the newly redesigned policy user interface. If you are looking for the former policy documentation, please refer to Thresholds.
Alerts can be added to tag and column policies to notify or to block users if a sensitive data access limitation has been exceeded and/or if sensitive data was queried outside of a designated time frame. When an alert is violated, a notification is sent to the user and the alert is logged on the Alerts page to be acknowledged and resolved.
There are two types of alerts:
Access rate—triggers an alert based on how many records a user accesses within a defined timeframe
Note
An alert triggers only after query results are returned and the query audit log is generated. Since ALTR doesn’t know the number of results until the query finishes, it cannot block the user before that. ALTR allows the query to complete, log the results and then block access if the alert criteria are violated.
Time window—triggers an alert based on the time of day or day of week that data was accessed
To add an alert to a policy:
Select Policy in the Navigation menu.
Create a new policy or edit an existing policy.
Click Add an alert.
Click the alert to apply. Options are:
values exceed [number] within every [time frame]. This is an access rate alert.
access on [day of week] in [time zone] between [time] and [time]. This is a time window alert.
Select the parameters for the alert.
(Optional) Select the Block users who violate this rule check box to restrict access to the protected column or tag for the offending user.
Click Save.
Add additional alerts to the policy as needed.
When an alert is triggered, you can see its details, such as when it was triggered and what rule statement triggered the alert.
To view active alerts, select Alerts on the Navigation menu.
Resolving alerts acknowledges the alert and restores normal access to the data if access was blocked.
To resolve an alert:
Select Alerts in the Navigation menu.
Click the alert you wish to resolve.
(Optional) Add a note to the alert to explain the violation in order to provide a record for future reference.
Click Notes tab to enter a note about the alert.
Enter a note to document details about the alert.
Click Post Note.
Click Overview tab.
Click Resolve Alert.
(Optional) Enter a description about why you are resolving the alert.
Click Resolve. If the alert was blocking user access, access will be restored once the alert is resolved.
To view alerts that have been resolved, click the Resolved Alerts tab.