Skip to main content

Threat Detection ManagementThreat Detection Management Guide

Analytics Engine Status

Determine the state and health of the analytics engine by monitoring analytics engine status.

View the status of the analytics engine under Engine Status:

Engine Status highlighted in a red rectangle.

The analytics engine displays one of the following statuses:

  • Triggering – The analytics engine is actively detecting threats in incoming events.

    tdm-analytics-engine-status-triggering.png
  • Pending changes – The analytics engine is actively detecting threats based in incoming events but has pending rule changes. To review and apply the rules changes, click View Changes.

    The Engine Status showing pending analytics rule changes waiting to be processed.
  • Inactive – There are no active analytics rules the analytics engine can use to evaluate incoming events. To start detecting threats, enable one or more analytics rules.

    tdm-analytics-engine-status-inactive.png
  • Training – The analytics engine is in a training period, assessing historical data to establish baselines. You can view its progress and how much time is left before the training period is completed.

    tdm-analytics-engine-status-training.png
  • Failure – The analytics engine has encountered an error and is not operational. The error was reported to Exabeam Support. After the issue is resolved, the analytics engine reprocesses and goes through a training period.

    tdm-analytics-engine-status-failure.png