Alarm Monitor#

The Scrutinizer Alarm Monitor subsection/page is Scrutinizer’s main interface for monitoring and investigating active alarm policy violations. The page is divided into three subtabs, which allow for different starting points when investigating events.

On this page:

Policies
Policies
Hosts
Hosts
ATT&CK
ATT&CK1
FLOWScore
FLOWScore
AI Insights
AI Insights

For additional background and recommended configuration steps related to Alarm Monitor functions, see the configuration guide for alarms and events.

Policies#

The Monitor > Policies tab/view is the default Alarm Monitor view and can be used to investigate alarms within the specified time period based on the alarm policy violated.

The overview table can be set to include any of the following columns via the Available Columns button:

  • Severity: Distribution of individual events under the policy based on severity

  • Risk: Aggregated risk level

  • Events: Total number of violating events under the policy

  • Violators: Total number of hosts observed as violators under the policy

  • Targets: Total number of hosts observed as targets under the policy

  • First Observed: Timestamp of the first violating event within the specified time period

  • Last Observed: Timestamp of the most recent violating event within the specified time period

  • Category: Policy category

  • Technology: Plixer One component where the alarm originated

The host counts in the Violators and Targets columns also function as shortcuts to pivot to the Hosts view with a filter for the policy applied.

Note

Editing policy settings#

To edit the settings of the policy for an active alarm, select Edit Policy from the three-dot menu in the list/table.

This will open the settings tray in the alarm policy management view, where the policy’s weight, timeout, and state can be modified. Notification profiles can also be created and assigned to the policy from this tray.

Inspecting hosts#

Clicking the ➝] icon in the Violators or Targets column of the table opens a tray listing violating and targeted hosts involved in the alarm. This tray can be used to select one or more hosts to apply as filters or view alarm details for any of the hosts involved.

Alternatively, clicking on the host count in the Violators or Targets column opens the Alarm Monitor Hosts tab with a filter for the policy applied.

The tray also includes toggles to hide/show system policy violations and acknowledged events in the active alarm list.

Managing exclusions#

To add or remove exclusions for an active alarm policy, select Manage Exclusions from the three-dot menu in the list/table.

For Scrutinizer alarm policies (indicated in the Technology column), this will open the FA algorithm management view, from where exclusions can be added to or removed from the algorithm driving the policy. For Plixer Machine Learning policies, the option will open the FA algorithm management view instead.

Individual hosts can also be added to FA algorithm or ML detection exclusion lists by opening the violators/targets tray and clicking the icon for one or more hosts.

Alarm summary#

Clicking on a policy in the main list opens the summary/details view for the alarm, which includes a chart/timeline summarizing observation details and a list of artifacts for separate events/violations under the same policy.

The following visualizations can be selected from the View dropdown:

  • Events Scatter Plot - Shows distribution of the events and observations

  • Events Timeline (default) - Shows the individual events and their durations in a timeline for the specified time period

  • Entities - Shows observation distribution among top violators, IP groups, and targets

Note

Scrutinizer aggregates continuous or consecutive observations within the policy’s Timeout setting as a single event. See this page on the alarm/event life cycle for further details.

Hint

Click the Tune Policy with AI (wand) button to allow the Plixer AI Assistant to analyze the current violation details and optimize the policy’s settings (requires AI write tools to be enabled in the Admin > Settings > AI settings menu/tray).

Event list#

The event list of the alarm summary view can be used to drill into the artifacts for discrete events/violations within the specified time period. The summary table lists total number of observations aggregated as well as the basic details (severity, hosts, etc.) for each event.

Hint

Mouse over the graph icon in the event list for additional shortcuts/options (varies by policy).

Click on an artifact to open a tray containing the full details for the event:

  • Severity

  • Start/end timestamps

  • Most recent event message generated

  • All hosts observed as targets

  • All hosts observed as violators

  • All events with matching violating criteria

In the tray, clicking on the link icon for target or violator opens the host details view, where the details for all alarms associated with the host can be investigated. Details for other events with the same violating criteria (based on the alarm policy) can also be viewed in a secondary tray by clicking the view (eye) icon.

Auto-Investigate policy#

The Auto-Investigate alarm policy reports sequential incident/event chains wherein each targeted host becomes the next violator in the sequence. Each chain includes all discrete events starting from the initial incident and ends when the target cannot be confirmed as the next violator.

When an Auto-Investigate alarm is active, its summary view will list all incident chains (aggregated by the initial violating host) instead of individual events.

Investigation details

Clicking the microscope icon in the list/table opens the investigation pane/subview for the selected initial violator, which can be used to inspect the following information for all incident chains linking back to it:

  • All incident chains with the same initial violator, including violators, targets, and exact timelines

  • Visualized links between violators, policies, and targets

  • Event distribution over time

  • Event, target, and violator counts for all policies violated

  • Number of policy violations, linked event violator counts (including itself), and roles for all hosts

The policy and host lists also link back to their respective Alarm Monitor views for further investigation and cross-referencing.

Hint

The investigation pane can also be accessed by clicking Show Investigation in the details tray for an artifact.

Hosts

The Monitor > Policies tab can be used to investigate alarms within the specified time period based on a target or violating host.

The overview table can be set to include any of the following columns via the Available Columns button:

  • Severity: Distribution of individual events under the policy based on severity

  • Behavior: Host behavior information (Click the icon to view behavior summary or drill into the host behavior subview.)

  • Risk: Endpoint risk level (Click the icon to view endpoint details.)

  • Country/Group: IP group or country associated with the host

  • As Target: Total number of events with the host as a target

  • As Violator: Total number of events with the host as a violator

  • Policies: Total number of policy violations involving the host as a target or violator

  • First Observed: Timestamp of the first violating event involving the host within the specified time period

  • Last Observed: Timestamp of the most recent violating event involving the host within the specified time period

The three-dot icon/menu can be used to access the host information summary tray or pivot to any report supported by the host.

Note

  • Behavior information requires a Plixer One Enterprise license.

  • Risk information requires Endpoint Analytics integration to be enabled.

  • The Country/Group column will display IP groups for internal hosts and countries for external addresses. Addresses can be designated as internal or external as part of IP group definitions.

Host details

Clicking on a hostname/address in the main list opens the host details page, which includes an overview pane and three (four if the host is an exporter) subviews with detailed insights related to the host’s activity.

Note

If Endpoint Analytics integration is enabled, the overview pane will include a section with additional endpoint information and a link to the corresponding Endpoint Analytics view.

Traffic

The host traffic subview can be used to inspect a host’s activity based on its communications with other hosts and/or IP groups.

This subview visualizes activity data for the host using the following charts:

  • An activity timeline showing the inbound (green) and outbound (blue) rates over the specified time period in an activity timeline

  • A traffic distribution chart of source IP groups where this host is the destination

  • A traffic distribution chart representing the host’s activity by defined application used

  • A traffic distribution chart of destination IP groups where this host is the source

Each chart also includes a shortcut button to run a filtered report to break down the host’s activity in greater detail.

Behavior

The host behavior subview can be used to investigate a host that has been observed by the Plixer ML Engine to be exhibiting anomalous behavior.

Host behavior insights for the selected ML dimension are summarized in the following:

  • A timeline showing the deviation criteria (e.g., bytes, IP address count, etc.), magnitude (based on the host’s typical activity patterns), and threshold for the selected dimension

  • A table/list of timestamps and details for individual behavior deviations

To see behavior information for a different feature dimension, use the dropdown and select another dimension with an anomalous behavior count.

Further investigation is recommended for hosts with deviation magnitudes exceeding the indicated threshold.

Note

  • Behavior data will only be available for hosts that are covered by the ML Engine’s inclusion rules and have exhibited anomalous behavior.

  • Behavior modeling and other ML Engine functions require a Plixer One Enterprise license. Contact Plixer Technical Support to learn more.

Alarms

The host alarms subview can be used to investigate alarms in which the host was involved as a target and/or violator.

This subview includes two overviews of all unacknowledged alarms associated with the host:

  • A timeline showing individual events by alarm policy violated

  • A summary table (similar to the main Alarm Monitor policies view) with details for all policies with violations involving the host

Drilling in from the summary table opens the alarm details view for the policy, where event artifacts can be inspected individually.

Interfaces

The host interfaces subview consists of a table listing all interfaces on a flow-exporting device along with their inbound and outbound activity details.

Note

Inbound and outbound activity details use rates by default. If custom interface speed has been assigned to an interface, utilization will be used instead.

To show highwater activity (inbound or outbound) details for an interface, hover over the corresponding information (i) icon in the table. Shortcuts to run reports or drill into interface traffic/behavior can be accessed from the three-dot menu.

Additional options

To support workflow efficiency, the host details page header includes buttons to access the following functions:

  • Changing the time period/range covered

  • Pivoting to any supported report type filtered on the current host

  • Viewing additional details and information from integrated sources (Learn more button)

  • Applying filters (alarms and interfaces subviews only)

ATT&CK[1]

The Monitor > ATT&CK tab can be used to investigate events based on the tactic, technique, and sub-technique assigned by the MITRE ATT&CK framework.

Events are plotted in a timeline, where the user is able to drill into them individually to open a tray containing the following:

  • MITRE ATT&CK tactic and technique information, with links to the relevant MITRE ATT&CK knowledge base articles

  • Shortcuts to the Policies or Hosts Alarm Monitor tab with filters for the event’s details applied

  • Basic event information

The page also includes the MITRE ATT&CK Enterprise Matrix, with technique classifications highlighted to match the corresponding events in the timeline.

Hint

Click on a technique cell in the matrix to view the policies violated in the Policies tab.

Applying filters

To further facilitate monitoring and investigation, the Scrutinizer Alarm Monitor views support multiple approaches to applying filters to the Alarm Monitor views.

Time range filter

The Alarm Monitor views can be set to show alarm/event information for either a custom date and time range or a specified Last X period (last 15 minutes, last 24 hours, last week, etc.).

To view data for a different period, click the Time Range (calendar) button and configure the range to apply.

Hint

  • When a custom range is specified, click the up/down arrows to automatically adjust the dates to cover the same period of time.

  • Custom date/time ranges are retained when drilling into or pivoting to other views. After returning to the main Alarm Monitor view, the range automatically resets to the default last 24 hours setting.

Card/chart filters

By default, the Policies and Hosts tabs use sparkline cards to summarize severity distribution across policies or hosts. These cards can be clicked to apply a filter for policy violations or hosts matching the selected severity.

Other visualization types (timelines and connection diagrams) showing different event details (events, alarm policy category, etc.), can be selected from the View dropdown and used to quickly apply the corresponding filter.

Advanced filters

Clicking the Filters button opens a tray where one or more filters can be manually configured.

The following filtering options are available:

  • Policy

  • Severity

  • Risk

  • Hosts

  • Violators

  • Targets

  • Category (of alarm policy)

To apply a filter, expand the filter option/section, and select the criteria to use. Multiple filters and criteria can be applied at the same time to further refine results.

Filter operators

  • Equal: Returns results that exactly match the specified value.

  • Like: Returns results that contain the specified search term.

  • Not Like: Excludes results that contain the specified search term.

An All Active option is also available, allowing filtering across all currently active values for the selected category.

Note

  • The Risk filter is only available when the Endpoint Analytics integration is enabled. To learn more about Endpoint Analytics integration in Scrutinizer, see this section of this documentation.

  • The filter options tray also includes an option to show policies and hosts associated with events that have already been acknowledged.

  • When exporting alarm/event data (via the Options button/tray), use the Export CSV (All) option to ignore any filters currently applied.

Acknowledging events#

Once an event has been investigated and/or resolved, it should be acknowledged to clear it from all Alarm Monitor views. This reduces the volume of active alarms and/or events at any given time and can further streamline investigative processes.

Acknowledging events is part of Scrutinizer’s recommended investigation and resolution workflow.

Hint

To show/hide acknowledged events in the Alarm Monitor views, open the filter options tray and toggle the Show Acknowledged Events option on/off.

Acknowledging can be done by alarm policy or by event.

Acknowledging by policy#

From the main view of the Policies tab, acknowledging an alarm policy automatically flags all events generated under the policy as acknowledged.

To acknowledge by alarm policy:

  1. While on the Policies tab of the Alarm Monitor view, select the policy by ticking its checkbox.

  2. If acknowledging more than one policy, verify that the correct policies have been selected.

  3. Click Acknowledge Selected Events.

Note

The Acknowledge Selected Events button is only available when at least one policy checkbox is ticked.

Once acknowledged, the alarm policy and all events associated with it will be hidden from all Alarm Monitor views.

Acknowledging by event#

Acknowledging can also be used to clear only events that match the same criteria. This allows other events under the same policy (as well as the alarm policy itself) to be retained in Alarm Monitor views.

Events are acknowledged from the summary view of the Policies tab as follows:

  1. Scroll down to the Event List section of the page.

  2. Select the artifact linked to the criteria/events to be acknowledged by ticking its checkbox.

  3. If selecting more than one artifact, verify that the correct checkboxes have been ticked.

  4. Click Acknowledge Selected Events.

Note

The Acknowledge Selected Events button is only available when at least one policy checkbox is ticked.

Once acknowledged, the event(s) will be hidden from all Alarm Monitor views.

FLOWScore#

Added in version 19.8.0: The FLOWScore view/feature is currently in beta and will have expanded functionality in future releases.

The Monitor > Alarm Monitor > FLOWScore tab provides an at-a-glance measure of the overall network health and security posture.

FLOWScore runs as a Golang application within Scrutinizer via the ProcMonitor client. It draws data from the Scrutinizer database and Reporting API to calculate scores for a set of defined metrics. These metric scores roll up into category scores, which then contribute to top-level NetOps and SecOps composite scores.

Setup#

FLOWScore runs automatically when Scrutinizer is installed. No additional installation steps are required.

To enable the FLOWScore tab in Monitor > Alarm Monitor, beta features must first be turned on in the Scrutinizer UI:

  1. Go to Admin > Settings > System Preferences.

  2. Check the Beta Features checkbox and click Apply.

  3. Navigate to Monitor > Alarm Monitor. The FLOWScore tab should now be visible.

Note

Enabling beta features turns on all available beta functionality in Scrutinizer, not only FLOWScore.

Configuring the Reporting API authentication token#

To use the Reporting API, FLOWScore requires a valid Scrutinizer administrator authentication token. To configure the token:

  1. Generate an auth token in the Scrutinizer UI under Admin > Users & Groups > Authentication Tokens.

  2. Add the token to /home/plixer/scrutinizer/env/local_env.

    export SCRUTINIZER_AUTH_TOKEN=tokenhere
    

Configuring the processing interval#

By default, FLOWScore waits 5 minutes between processing runs. This setting is not yet configurable through the Scrutinizer UI. To change this interval, update the flowscore_sleep_minutes server preference via psql on Scrutinizer.

For example, to set the interval to 10 minutes:

update serverprefs set currentval=10 where langkey='flowscore_sleep_minutes';

Collector port#

FLOWScore exports IPFIX to Scrutinizer using the port defined by the SystemFlowsPort server preference. If an error is encountered fetching this value, port 4739 is used.

Viewing FLOWScore#

The FLOWScore view is divided into the following sections:

  • Composite score bar and percentage: Displays the current composite score (NetOps or SecOps, depending on the selected view) as a percentage and a proportional color bar representing each contributing category.

  • Action Items: Lists the top metrics with the lowest scores, sorted by priority. Each action item includes the metric name, its associated category, and its current score. Clicking an action item opens a tray that displays a description of the action item and recommended remediation steps.

  • Category score cards: Shows a donut chart for each category, displaying the category’s current score as a percentage. Each arc segment within a donut chart represents an individual metric contributing to that category.

  • Timeline: Displays the historical trend of composite and category scores over the selected time period. Each color band corresponds to a category.

  • View selector: Use the View dropdown in the upper-right corner of the page to switch between the NetOps and SecOps composite score perspectives.

Metrics#

The following describes what each metric measures and what it reflects about the network environment.

Note

Several metrics use data from a fixed default time range (e.g., last 24 hours, last 30 days). These ranges can be made configurable if needed.

NetOps metrics#

config_checklist

Reflects how many features in the configuration checklist have been configured. A higher score indicates that more recommended features are enabled and in use.

interface_utilization_avg

Reflects how close average interface utilization is to the target utilization benchmark. Interfaces that are significantly over- or under-utilized will lower the score, with over-utilization penalized more heavily than under-utilization.

jitter_quality_score

Reflects the average jitter observed across the network over the past 24 hours. A higher score indicates that jitter is within acceptable levels; the score decreases as average jitter increases beyond the benchmark.

exporter_uptime_percentage

Reflects how consistently enabled exporters have been reporting traffic over the past 24 hours. A higher score indicates that exporters are reliably active and sending data to Scrutinizer.

firewall_event_health

Reflects the volume and diversity of denied traffic observed over the past 24 hours. A higher score indicates fewer denied flows and fewer unique hosts involved in denied connections.

avg_host_event_score

Reflects the overall policy hit activity across internal hosts over the past 24 hours. A higher score indicates that fewer hosts are triggering policy violations, and that the violations observed are lower in severity.

application_traffic_patterns

Reflects the degree to which application traffic patterns deviate from expected behavior over the past 24 hours, based on ML-detected anomalies. A higher score indicates fewer or less significant deviations.

Note

application_traffic_patterns is disabled by default. It is enabled automatically if an ML Engine is detected at startup or when an ML Engine is configured later. Weights are updated accordingly.

seen_vs_monitored_traffic

Reflects how much of the network traffic observed is actively monitored by the ML Engine. A higher score indicates that a greater proportion of hosts with active traffic are covered by ML monitoring.

Note

seen_vs_monitored_traffic is disabled by default. It is enabled automatically if an ML Engine is detected at startup or when an ML Engine is configured later. Weights are updated accordingly.

SecOps metrics

host_severity_score

Reflects the proportion of hosts with high-severity events over the past 24 hours. A higher score indicates that fewer hosts are generating events of medium severity or higher.

facts_generation_rate

Reflects whether the rate at which security facts are being generated is within the expected range relative to overall flow volume. A higher score indicates that the facts generation rate is close to the industry standard of approximately 1 fact per 1,000 flows.

ml_system_health

Reflects the overall operational health of the Plixer ML Engine. The score takes into account whether ML engines are deployed and running, the frequency of down alerts, and whether models and documents are being generated as expected.

Note

ml_system_health is disabled by default. It is enabled automatically if an ML Engine is detected at startup or when an ML Engine is configured later. Weights are updated accordingly.

incident_response_time

Reflects how quickly security events are being acknowledged and resolved over the past 30 days. A higher score indicates that events are being addressed promptly, with fewer long-running unacknowledged events.

policy_class_distribution

Reflects how well active policies are distributed across policy classes and how broadly they cover the available policy types. A higher score indicates that policies are both evenly distributed and cover a greater proportion of the available policy classes.

exporter_error_rate

Reflects the rate at which exporters are dropping flows relative to total flow volume over the past 24 hours. A higher score indicates a lower error rate and more reliable flow data being sent to Scrutinizer.

Database schema#

FLOWScore uses a dedicated flowscore schema in the Scrutinizer PostgreSQL database.

Tables and views#

  • flowscore.metrics_and_categories: The primary table containing all FLOWScore configuration and the latest calculated values.

    Key columns

    Column

    Description

    enabled

    true if the metric is active; false if disabled

    composite_name

    secOps or netOps

    category_name

    Name of the metric’s associated category

    metric_name

    Name of the metric

    category_weight

    Weight of the category within the composite (sums to 1 per composite)

    metric_weight

    Weight of the metric within the category (sums to 1 per category)

    is_network

    true if the metric is network-related

    benchmark

    Target value for the metric; always factored into the final score

    value

    Most recently calculated raw or normalized value for the metric

    score

    Current final score (out of 100); benchmark has already been applied

    description

    Description of the metric

    remediation

    Recommended steps for improving the score or addressing issues

  • flowscore.latest_metric_scores: A view returning the names and latest weighted scores for all enabled metrics.

  • flowscore.latest_category_scores: A view returning the names and latest weighted scores for all enabled categories.

  • flowscore.latest_composite_score(composite_name): Returns the weighted composite score for a given composite (secOps or netOps), based on all currently enabled metrics and categories.

  • flowscore.latest_overall_score(): Returns the latest overall FLOWScore, which is a combination of the SecOps and NetOps composite scores with all weights applied.

Sample queries#
Get the current SecOps composite score
select * from flowscore.latest_composite_score('secOps') as secops_score;
Get the current NetOps composite score
select * from flowscore.latest_composite_score('netOps') as netops_score;
Get the latest overall score
select * from flowscore.latest_overall_score();
Verify metric weight totals for each category
select category_name, sum(metric_weight)
from flowscore.metrics_and_categories
where enabled=true
group by category_name;
Verify category weight totals for NetOps
with categories as (
    select distinct category_name, category_weight
    from flowscore.metrics_and_categories
    where enabled=true and composite_name='netOps'
)
select sum(category_weight) from categories;
Verify category weight totals for SecOps
with categories as (
    select distinct category_name, category_weight
    from flowscore.metrics_and_categories
    where enabled=true and composite_name='secOps'
)
select sum(category_weight) from categories;

Reports#

There are four FLOWScore reports available under the FLOWScore report type in Reports > Run Report.

Report

Description

NetOps Categories

Category name, category weight, and unweighted score for NetOps categories

NetOps Metrics

Metric name, category name, and unweighted score for NetOps metrics

SecOps Categories

Category name, category weight, and unweighted score for SecOps categories

SecOps Metrics

Metric name, category name, and unweighted score for SecOps metrics

AI Insights#

The Monitor > Alarm Monitor > AI Insights tab/view is used to access the insight summaries generated by the nightly NOC and SOC AI agents of the Plixer AI Assistant.

Note

The NOC and SOC AI agents can be enabled alongside the AI assistant from the Admin > Settings > AI Settings tray/menu.

The AI Insights tab displays NOC and SOC summaries in separate subviews, which can be accessed from the View dropdown.

NOC and SOC insight summaries#

The NetOps Summary and SecOps Summary subviews display the latest insight summary generated by the corresponding AI agent. New summaries are automatically added after the agents complete their nightly workflows.

Each insight summary includes the following elements:

  • Executive Summary: Overview of the alarms investigated by the agent as well as the resulting findings

  • Risk Score: Approximated risk score (higher = greater risk) based on the agent’s findings

  • Remediation: Recommended steps to address the issues that triggered the alarms

  • Collection: A collection of all elements (alarms, reports, hosts, etc.) involved in the agent’s investigation

The Collection section of the summary can be expanded to inspect the included elements and any notes added by the agent.

To view a past NOC or SOC agent summary instead of the latest, click on the corresponding date in the main NetOps Summary or SecOps Summary view. The NetOps Collections and SecOps Collections subviews (selected from the dropdown) list all available summaries and can be used to jump directly to the expanded summary views.