> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/content-collections/administration/anomalies/anomaly-thresholds.md).

# Anomaly Thresholds

Prisma Cloud allows you to define different thresholds for anomaly detection for Unusual Entity Behavior Analysis (UEBA) that correspond to policies which analyze audit events, for unusual network activity that correspond to policies which analyze network flow logs, for DNS analytics, and for identity. You can also define your preference for when you want to alert notifications based on the severity assigned to the anomaly policy.

If you want to exclude one or more IP addresses or a CIDR block from generating alerts against Anomaly policies, see [Trusted IP Addresses on Prisma Cloud](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/administration/anomalies/trusted-ip-addresses-on-prisma-cloud.md).

1. For UEBA policies:
   1. Select **Settings > Anomaly Settings > Alerts and Thresholds**.

      <figure><img src="/files/DJrj0mCEqaAb2YuY7eff" alt="anomaly policies ueba settings 1"><figcaption></figcaption></figure>
   2. Select a policy.
   3. Define the **Training Model Threshold**.

      The Training Model Threshold informs Prisma Cloud on the values to use for setting the baseline for the machine learning (ML) models.

      For production environments, set the **Training Model Threshold** to **High** so that you allow for more time and have more data to analyze for determining the baseline.

      **For account hijacking attempts:**

      1. Low: The behavioral models are based on observing at least 10 events over 7 days.
      2. Medium: The behavioral models are based on observing at least 25 events over 15 days.
      3. High: The behavioral models are based on observing at least 50 events over 30 days.**For anomalous compute provisioning activity:** None.

         **For unusual user activity:**
      4. Low: The behavioral models are based on observing at least 25 events over 7 days.
      5. Medium: The behavioral models are based on observing at least 100 events over 30 days.
      6. High: The behavioral models are based on observing at least 300 events over 90 days.
   4. Define your **Alert Disposition**.

      Alert Disposition is your preference on when you want to be notified of an alert, based on the severity of the issue —low, medium, high. The alert severity is based on the severity associated with the policy that triggers an alert.

      You can profile every activity by location or user activity. The activity-based anomalies identify any activities which have not been consistently performed in the past. The location based anomalies identify locations from which activities have not been performed in the past.

      Choose the disposition (in some cases you may only have two to choose from):

      1. Conservative:

         For unusual user activity—Reports on unknown location and service to classify an anomaly.

         For account hijacking—Reports on location and activity to login under travel conditions that are not possible, such as logging in from India and US within 8 hours.

         For anomalous compute provisioning activity—Reports on high severity alerts only when an unusual number of instances are created within a short time interval, impossible time travel, and belonging to a TOR anonymity network.
      2. Moderate:

         For unusual user activity—Report on unknown location, or both unknown location and service to classify an anomaly.

         For anomalous compute provisioning activity—Reports on medium and higher severity alerts.
      3. Aggressive:

         For unusual user activity—Reports on either unknown location or service, or both to classify an anomaly.

         For account hijacking—Reports on unknown browser and Operating System, impossible time travel, or both.

         For anomalous compute provisioning activity—Reports on low and higher severity alerts.

         Set the **Alert Disposition** to **Conservative** to reduce false positives.

         When a Prisma Cloud administrator modifies the **Alert Disposition** or **Training Model Thresholds** for detecting anomalies that relate to UEBA, existing alerts associated with UEBA policies will no longer be resolved, but instead, remain as-is. Additionally, an audit log is generated to record who made the configuration change and when, to help you track and monitor changes.
2. For unusual network activity.

   For anomalies policies that help you detect network incidents, such as unusual protocols or port used to access a server on your network, you can customize the following for each policy.

   1. Select **Settings > Anomalies > Alerts and Thresholds**.
   2. Select a policy.

      <figure><img src="/files/11vFpJL4N7Hyj4Gh2Byi" alt="anomaly policies network settings"><figcaption></figcaption></figure>
   3. Define the **Training Model Threshold**.

      The Training Model Threshold informs Prisma Cloud on the values to use for various parameters such as number of days and packets for creating the ML models. These thresholds are available only for the policies that require model building such as Unusual server port activity and Spambot activity.

      1. Low: The behavioral models are based on observing at least 10K packets over 7 days.
      2. Medium: The behavioral models are based on observing at least 100k packets over 14 days.
      3. High: The behavioral models are based on observing at least 1M packets over 28 days.
   4. Define your **Alert Disposition**.

      Alert Disposition is your preference on when you want to be notified of an alert, based on the severity of the issue —low, medium, high. The alert severity is based on the severity associated with the policy that triggers an alert. You can choose from three dispositions based on the number of ports, hosts or the volume of traffic generated to a port or host on a resource:

      1. Aggressive: Reports High, Medium, and Low severity alerts.

         For example, a Spambot policy that sees 250MB traffic to a resource, or a port sweep policy that scans 10 hosts.
      2. Moderate: Reports High and Medium severity alerts.

         For example, a Spambot policy that sees 500MB traffic to a resource, or a port sweep policy that scans 25 hosts.
      3. Conservative: Reports on High severity alerts only.

         For example, a Spambot policy that sees 1GB traffic to a resource, or a port sweep policy that scans 40 hosts.
3. For unusual usage of workload credentials.

   For anomalies policies that help you detect when a credential that has been assigned to a compute resource, such as an EC2 instance, is used from inside the cloud service provider.

   1. Select **Settings > Anomalies > Alerts and Thresholds** and scroll down to **Identity**.
   2. Select a policy.

      <figure><img src="/files/a9tK6IXEu3bSH6qf8prg" alt="anomaly policies identity settings"><figcaption></figcaption></figure>
   3. Define your **Alert Disposition**.

      Alert Disposition is your preference on when you want to be notified of an alert. For unusual usage of workload credentials policies, this only applies when the suspicious IPs are inside the cloud because the policy is more prone to false positives when the suspicious IPs are inside the cloud provider’s IP space. When the suspicious IPs are outside the cloud provider’s IP space, alerts are always generated irrespective of the alert disposition setting.

      1. Aggressive: Alerts are generated only when the suspicious IP is inside the cloud and it resides within or outside the monitored cloud accounts.
      2. Moderate: Alerts are generated only when the suspicious IP is inside the cloud and it is a private IPv4 or it is outside the monitored cloud accounts.
      3. Conservative: Alerts are generated only when the suspicious IP is inside the cloud but outside of the monitored cloud accounts.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/content-collections/administration/anomalies/anomaly-thresholds.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
