Manage alerts and blocked users in NetApp Ransomware Resilience
After configuring user behavior monitoring in NetApp Ransomware Resilience, you can customize alerts and manage blocked users. Customizing the alerts allows you to exclude specific users or file paths from generating an alert. Blocking users is meant to respond to ransomware events to prevent malicious user activity.
You must have configured a user activity agent, enabled a policy with user activity detection, and created a user directory connector to block users.
|
|
You can automate responses to user activity detection events. |
Manage blocked users
You can block users when you believe they're responsible for malicious activity.
-
In Ransomware Resilience, select Settings.
-
In the Settings dashboard, locate the User activity monitoring tile then select Manage.
-
Select the Users tab.
-
Select Block users.
-
Select the duration of the blocking: it can be one hour up to 24 hours or permanent.
-
Select the checkbox next to the names of the users you want to block.
-
Select Block.
-
In Ransomware Resilience, select Settings.
-
In the Settings dashboard, locate the User activity monitoring tile then select Manage.
-
Select the Users tab.
-
Select Edit user blocking.
-
Choose the modification. To modify the duration of the blocking, select Time period for blocked users then modify the duration. To remove users from the blocked user list, select Unblock users.
-
Select the checkbox next to the name of the blocked user whose status you want to change.
-
Select Save.
Exclude users from alerts
If there are certain trusted users whose behavior might trigger user behavior alerts, you can exclude them from alerts.
-
In Ransomware Resilience, select Settings.
-
In the Settings dashboard, locate the User activity monitoring tile then select Manage.
-
Select the Excluded from monitoring tab.
-
To review individual users in the UI, choose Select manually. To upload a list of excluded users, select Upload.
-
If you selected Select manually, select the checkbox next to the names of the specific users you want to exclude.
-
If you select Upload, download the CSV or JSON file that includes the list of all the users. Select Download to access the list.
On your local machine, review the file. Remove the names of all users that you want to maintain detection for. When the list includes only the names of users you want to exclude from detection, save it.
In Ransomware Resilience, select Upload. Locate and upload the file.
-
-
Select Add to complete adding the users to the exclusion list.
-
In the Excluded from monitoring tab, the names of the users removed from user behavior detection alerts now display in the dashboard.
|
|
You can also exclude a user directly from an alert. For more information, see Respond to ransomware alerts. |
-
In the Settings dashboard, locate the User activity card then select Manage.
-
Select the Excluded from monitoring tab.
-
Select Add.
-
To exlcude individual users from the UI, choose Select manually.
-
Locate the name of the user you want to remove from the excluded user select. Select the action menu (
…) on the row with the user's name then Remove. -
In the dialog, select Remove to confirm you want to remove the selected users.
Exclude file paths from monitoring
Each file path must begin with a volume name. It can include up to three sub-directories for that volume, for example "volume/directory/subdirectory/subdirectory2". You can exclude file paths by entering them manually or uploading a CSV file that lists the paths.
-
In Ransomware Resilience, select Settings.
-
In the User activity monitoring tile, select Manage.
-
Select the Excluded from monitoring tab.
-
Select Add to enter the file paths for exclusion.
-
To enter the file paths in the UI, select the Enter manually radio button then enter the file path, for example "volume/directory/subdirectory/". To enter additional file paths, select Select file path.
-
To upload a list of file paths, select the Upload radio button. Select the upload button to choose the CSV file.
-
Select Add.
When the operation completes successfully, Ransomware Resilience begins excluding files in the selected paths from monitoring for suspicious user behavior. You can review the list of paths at any time from the Settings menu. If you need to enable monitoring for the file paths again, you can remove them from the list.