32. Reports » Tools » Anomalies

The Anomalies tab displays live and historical traffic anomaly data. It is split into the five sub-tabs listed along its bottom edge, which can be dragged into whatever order suits you.

32.1. Active Anomalies

Lists the anomalies that are still ongoing, re-reading them from the database every 5 seconds. The top bar decides what is listed, and how:

Sensor Interfaces – Restrict the listing to anomalies detected by the selected Sensor Interfaces
Decoders – Restrict the listing to anomalies of the selected decoders
Responses – Restrict the listing to anomalies handled by the selected Responses
Display – How much of each anomaly is shown:
Minimal – The columns №, Prefix, IP Group, Anomaly, Speed (Latest), Sensor Interface, From, Pkts/s - Bits/s and Severity. There is no Actions column, and mitigation information is never shown
Compact – Adds the Latest Alarm and Actions columns
Extended – Adds the Response and Classification columns
Full – The default. Drops the Response column and expands every anomaly with the block of details described further below
Display Options – A menu of presentation settings, each of them remembered for your next visit:
Count – List All the anomalies, or only the top 1, 5, 10, 20, 30 or 50
Comments – Show the comment row always (On), only when a comment exists (Auto, the default), or never (Off)
Direction – Restrict the listing to All, Inbound, or Outbound anomalies
Histogram – The graph drawn inside each anomaly row when Display is Full: None; Auto, the default; a decoder rate (Decoder Pkts/s In, Decoder Pkts/s Out, Decoder Bits/s In, Decoder Bits/s Out); an IP rate (IP Pkts/s In, IP Pkts/s Out, IP Bits/s In, IP Bits/s Out); a Filter rate (Filter Pkts/s, Filter Bits/s, Filter Src IPs); a firewall drop rate (FW Drop Pkts/s, FW Drop Bits/s); or an IP Graph, spanning either the anomaly alone or a window widened by ±5m, ±15m, ±30m, ±1h, ±3h, ±6h or ±1d around it
Sort By – Order the anomalies by Date (the default, newest first), Duration, IP Address, Mask, IP Group, Anomaly, Speed, Latest Alarm, Latest Speed, Pkts/s, Bits/s, or Severity
Mitigation Info – How much of the filtering-rule table inside each anomaly row is shown: None, Basic, or Full
Show DNS – Resolve IP addresses to hostnames
Actions – The [Batch] menu acts on every active anomaly at once, after asking for confirmation:
Expire – Expires the anomalies, which then end the way they would have ended on their own. The Sensor that detected an anomaly must be running for it to expire
Reset – Marks the anomalies as finished straight away, without expiring them. Any BGP announcement they made is left orphaned, and their Response actions are not executed
Refresh – Regenerate the listing every 5, 10, 15, 30 or 45 seconds, or every 1, 2, 5, 10 or 15 minutes. Generate regenerates it only when you click the button

The Actions panel is hidden from a Guest user whose role does not grant Anomalies Actions. The same permission governs the per-anomaly Enable Manual Action(s), Classify / Set Comment, Delete BGP Announcement and Expire Anomaly buttons.

When Display is set to Full, each column represents:

Unique index of the anomaly.

Prefix

The prefix (IP address/class) involved in the anomaly. Clicking opens a new tab with details. The arrow before the prefix shows direction: ↓ for inbound, ↑ for outbound. If a cloud icon appears on the right, the IP is external (not in the IP Zone).

IP Group

Name of the IP Group containing the prefix. Clicking opens a new tab with details.

Anomaly

Brief description of the threshold that triggered the anomaly.

Speed (Latest)

Peak value of the abnormal traffic. The most recent value is in parentheses.

Sensor Interface

Name of the detecting Sensor, plus the interface if it’s a Flow Sensor or SNMP Sensor. Clicking opens a new tab with details.

From

Date/time when the anomaly began.

Latest Alarm

Time elapsed since the last detection of the anomaly.

Pkts/s - Bits/s

Latest pkts/s and bits/s recorded for the anomaly’s decoder.

Classification

Displays the current classification (Unclassified, False Positive, Possible Attack, Trivial Attack, Verified Attack, or Crippling Attack), color-coded. Use Classify / Set Comment in the Actions column to change it.

Severity

A graphical bar showing the ratio of abnormal traffic to the threshold value. Each bar = 100% of threshold.

The color denotes the link severity: 0–25% = blue, 25–50% = yellow, 50–75% = orange, 75–100% = red. For pkts/s, it’s the ratio of abnormal traffic to overall link traffic (Sensor or interface). For bits/s, it’s the ratio of abnormal traffic to link capacity.

Exact rule severity and link severity appear as a tooltip.

Actions

Generate Anomaly Report → Opens a tab with a full anomaly report.

Enable Manual Action(s) → Runs all Response actions set for manual execution.

Classify / Set Comment → Lets you classify anomaly impact and add/edit comments (for reporting only, not IP profiling).

Open Packet Dump → Available for Packet Sensors if a capturing action is in Response.

Open Flow List → Available for Flow Sensors if Flow Collector is enabled. Shows bi-directional flows for the selected time (possible 5-minute delay due to flow data file buffering). Time zone differences are not adjusted.

View Live Graph → Opens the live graph viewer for the prefix. When Display is Full, it is offered only if the anomaly has graph data.

Delete BGP Announcement → If a BGP prefix announcement exists.

Expire Anomaly → Immediately clears the anomaly; the Sensor must be running.

Also when Display is set to Full, a block inside each anomaly row shows the graph chosen under Display Options » Histogram, alongside:

AS Number

The autonomous system that the prefix belongs to, or 0 when unknown. Hovering over the number shows the AS description.

Decoder

The decoder (traffic type) of the anomaly. Hovering over the name shows the decoder’s description.

Threshold

The numeric threshold that triggered the anomaly, as defined in its rule. For profiled anomalies, this threshold changes dynamically based on the behavioral traffic graph (see Reports » IP Addresses » [Subnet] » Profile Graphs).

Overall Traffic

Percentage of decoder traffic relative to the prefix’s total IP traffic.

IP Zone (Prefix)

Indicates the IP Zone the Sensor used. Clicking opens the most specific prefix’s settings.

Threshold Template

Specifies which Threshold Template contains the anomaly’s threshold rule (if any).

Response (Actions)

Name of the Response and a list of any executed actions with Record Action enabled.

Comment

Shown according to Display Options » Comments: with Auto (the default), the row is hidden if no comment exists. Use Classify / Set Comment (in Actions) to add or edit.

When Wanguard Filter detects a filtering rule, Display is not Minimal, and Display Options » Mitigation Info is set to Basic or Full, the table below becomes visible within the anomaly row (the Firewall, Scrubbed, Pkts, and Bits columns require Full). In most themes, the active filtering rules have a pink/red background, and the inactive ones have a yellow background.

Filter

Identifies the detecting Wanguard Filter. Clicking opens a new tab with details.

Filtering Rule

Describes the rule matching malicious traffic or a default-applied rule. If a white flag appears, the rule conflicts with a whitelist rule entry. An Implicit Rule badge marks default-applied rules, and IP-based rules show a country flag whose tooltip indicates the country and ISP.

The filtering rules enabled for the decoder are listed in General Settings » Anomaly Mitigation.

Started

Date/time when the rule was created.

Latest Alarm

Most recent time the rule detected above-threshold traffic.

Pkts/s (Peak)

Current packets/second matching the rule, with the maximum value in parentheses.

Bits/s (Peak)

Current bits/second matching the rule, with the maximum value in parentheses.

Firewall

Icons show which backend applied the rule: Netfilter, Dataplane, Hardware Offload, BGP Flowspec/S/RTBH, or Third-party.

Scrubbed

Approximate percentage of mitigated abnormal traffic. Not all backends accurately report drops.

Pkts

Total packets matched by the rule.

Bits

Total bits matched by the rule.

Actions

Activate Netfilter Firewall / Activate Dataplane Firewall / Activate Hardware Offload → Shown for rules whose firewall activation is set to manual; applies the corresponding firewall rule.

Open Packet Dump → For Packet Filters if the Response includes traffic capturing.

Open Flow List → For Flow Sensors with the Flow Collector feature enabled, shown for non-implicit rules with a flow filtering expression. Displays bi-directional flows from the chosen time range (potential 5-minute delay, no time zone adjustment).

Expire Filtering Rule → Immediately clears the rule and associated firewall entries.

The Classify / Set Comment action opens the Anomaly #N Classification & Comments window. It holds the Anomaly Classification (Unclassified, Crippling Attack, Verified Attack, Trivial Attack, Possible Attack, or False Positive), an Anomaly Description that replaces the text of the Anomaly column once you set it, a free-form Comments area, and the Escalated and Customer Call checkboxes.

Note

The per-anomaly graph is generated only when Display is Full. With hundreds of active anomalies that makes the sub-tab slow to load; set Display Options » Histogram to None, or lower Display to Extended, to stop generating the graphs.

32.2. Anomaly Archive

A paged grid of every recorded anomaly, newest first, 100 rows at a time. Click the down arrow on any column header to sort the grid, filter it, or hide columns. The [+] button in the first column — or a double-click anywhere on the row — expands an anomaly to show its mitigation data and other details.

Sensor Interfaces – Restrict the grid to anomalies detected by the selected Sensor Interfaces
Row Filtering Expression – An SQL-style condition on the columns of the grid, applied when you press Enter. Write the column names as they appear in the header, in any case, and enclose the ones containing a space in double quotes: "IP Group" = 'Customers' AND Speed > '1G'. Speeds, thresholds and packet or bit counts accept a K, M or G suffix; Duration accepts a run of w, d, h, m and s parts, with or without spaces between them, as in Duration > '1h30m'; From and Until accept a date; and the columns that display words rather than numbers accept those same words, as in Status = 'Active' AND Classification = 'Verified Attack'. The star button opens the Anomaly Archive Filter bookmarks, where frequently used expressions can be stored and recalled
Display – How many columns the grid shows:
Compact – The default: №, Prefix, IP Group, Anomaly, Speed, Sensor Interface, From, Duration, IP Pkts/s, IP Bits/s, Severity and Actions
Extended – Adds Status, Direction, Domain, Until, IP Packets, IP Bits, Response, IP Zone, Mitigated, Comments, Classification and Link Severity
Full – Adds Decoder, Unit, Comparison, Threshold, Threshold Type, Computed Threshold, IP Address, IP Version, Mask, AS Number, Class, Threshold Template, Latest Speed, Pkts/s, Bits/s, Expiration, Captured Packets, Flow Collector, Filters, Filtering Rules, BGP Diversion, BGP Blackhole and Manual Actions
Export – Print or export the grid
Refresh – Reload the grid on demand, or every 5 seconds up to every 15 minutes

Columns shared with the previous section are described there. Status is Active while the anomaly is ongoing, Pending while it expires, and Finished once it has ended.

The Actions column of every row offers Generate Anomaly Report, and either Open Packet Dump or Open Flow List when the anomaly captured one. Set Classification & Comments opens the window described above, and Delete Traffic Anomaly removes the anomaly from the archive; both of them require the Anomalies Actions permission.

32.3. Anomaly Overview

Offers trends and summaries of detected anomalies for the selected Sensor Interfaces, decoders and time range, the last month by default. Drag a rectangle across any graph to zoom every graph into that interval, which switches the Time Range to Custom:

Graphs – Select one or more graphs: anomalies per second, hour, day, week, month, or year; Filter instances, BGP diversions, and BGP blackholes per hour, day, week, or month; and Highest/Stacked variants of Rule Severity, Link Severity, Pkts/s, and Bits/s
Top – The number of items charted: 5, 10 (the default), 15, 20, 25, 50, 75, 100, 250, 500 or 1000
Consolidation – Reduces data resolution by consolidating values over fixed time intervals, taking the Minimum, the Average, or the Maximum (the default) of each interval
GroupingSensor Interfaces, ticked by default, combines the data of all selected Sensor Interfaces into a single graph
StackingDecoders, ticked by default, displays summed, stacked values for multiple decoders
Export – Print, export, or email the graphs

32.4. Anomaly Distribution

Generates pie or donut charts of anomaly-related statistics, for the selected Sensor Interfaces, decoder and time range, the last month by default:

Data Units – Select one or more statistics: Most Used, Decoders, Sensor Interfaces, Prefixes, Severity, Link Severity, IP Version, IP Groups, Threshold Templates, Duration, Responses, Filters, Filtering Rules, BGP Diversion, BGP Blackhole, Classification, Anomaly Class, Anomaly Domain, Anomaly Direction, Anomaly Data Unit, Anomaly Threshold Type, Anomaly Comparison
Chart TypePie (the default), Pie v2, Pie v3, Donut, Donut v2, or Donut v3
Chart SizeTiny, Small, Medium (the default), Large, or Huge
Chart TitleAuto generates the title automatically, while None omits it
Slice Label – Controls how the chart slices are labeled: Labels In, Labels In v2v4, Labels Out, or Legend (the default)

32.5. Geo Distribution

Displays an interactive world map that highlights the selected Data Unit for each country: Anomalies, Avg. Pkts/s, Max. Pkts/s, Avg. Bits/s, or Max. Bits/s. The data can be narrowed down by Filter, decoder, and time range. This sub-tab is listed only when a Wanguard Filter license is installed.