Skip to main content

3-FSAC Exceptions Job

The 3-FSAC Exceptions job is designed to analyze collected access information for exceptions.

Parameter Configuration

The Configuration section on a Job's overview page allows you to easily modify any customizable parameters used by analysis tasks in the job. See the Parameter Configuration topic for instructions on how to edit parameters on a job overview page.

The 3-FSAC Exceptions job has many customizable parameters. See the Customizable Analysis Tasks for the 3-FSAC Exceptions Job topic for information on these.

Analysis Tasks for the 3-FSAC Exceptions Job

View the analysis tasks by navigating to the FileSystem > 0.Collection > 3-FSAC Exceptions > Configure node and select Analysis.

CAUTION: Do not modify or deselect the selected analysis tasks. The analysis tasks are preconfigured for this job.

Analysis Tasks for the 3-FSAC Exceptions Job

The following analysis tasks are selected by default:

  • Unusual share activity – Share exceptions for unusual volumes (spikes) of activity
  • First time access to share – Recent share access by users for the first time
  • Sensitive data activity – Recent access to sensitive content
  • Unusual peer group share activity – Spikes in interdepartmental activity
  • Unusual binaries activity – First time user activity performed on binaries
  • Unusual user activity – Spikes in activity by user
  • Unusual user sensitive data activity – Spikes in sensitive data activity by user
  • Ransomware – Spikes in updates by user
  • Unusual user stale data activity – Spikes in stale data activity by user

While it is possible to deselect particular tasks as specified, it is not recommended. The following analysis tasks are deselected by default:

  • Show view – Displays the SA_FSAC_ExceptionsView within the Results node of the Access Analyzer Console
  • Show users view – Displays the SA_FSAC_UserExceptionsView within the Results node of the Access Analyzer Console

Customizable Analysis Tasks for the 3-FSAC Exceptions Job

Customizable parameters enable users to set the values used for classification during the job’s analysis. The 3-FSAC Exceptions job contains the following customizable parameters:

Analysis TaskCustomizable Parameter NameDefault ValueValue Indicates
Unusual share activity@WEEKS3Minimum data points required for analysis
Unusual share activity@THROWAWAY1When calculating averages throw away the top N%
Unusual share activity@EVENTS10Minimum amount of events for operations exception
Unusual share activity@PEOPLE10Minimum amount of people for user activity exception
Unusual share activity@FILES10Minimum amount of files for resource count exception
Unusual share activity@DAYS7Amount of days to generate exceptions for from today
Unusual share activity@EVENTSTDDEVS3Multiples of standard deviation required to be an operation count exception
Unusual share activity@TRUSTEESTDDEVS3Multiples of standard deviation required to be a user volume exception
Unusual share activity@FILESTDDEVS3Multiples of standard deviation required to be a file activity volume exception
First time access to share@DAYS7Amount of days to generate exceptions for from today
First time access to share@MINDAYS30minimum amount of days a share needs to determine access
Sensitive data activity@DAYS7Amount of days to generate exceptions for from today
Unusual peer group share activity@WEEKS3Minimum data points required for analysis
Unusual peer group share activity@THROWAWAY1When calculating averages throw away the top N%
Unusual peer group share activity@EVENTS10Minimum amount of events for operations exception
Unusual peer group share activity@FILES10Minimum amount of files for resource count exception
Unusual peer group share activity@DAYS7Amount of days to generate exceptions for from today
Unusual peer group share activity@EVENTSTDDEVS3Multiples of standard deviation required to be an operation count exception
Unusual peer group share activity@FILESTDDEVS3Multiples of standard deviation required to be a file activity volume exception
Unusual binaries activity@DATE_CUTOFF7From the current time, how many days to look back when considering exceptions
Unusual user activity@WEEKS3Minimum data points required for analysis
Unusual user activity@THROWAWAY1When calculating averages throw away the top N%
Unusual user activity@EVENTS10Minimum amount of events for operations exception
Unusual user activity@SHARES10Minimum amount of shares for share activity exception
Unusual user activity@FILES10Minimum amount of files for resource count exception
Unusual user activity@DAYS7Amount of days to generate exceptions for from today
Unusual user activity@EVENTSTDDEVS3Multiples of standard deviation required to be an operations exception
Unusual user activity@GATESTDDEVS3Multiples of standard deviation required to be a share exception
Unusual user activity@FILESTDDEVS3Multiples of standard deviation required to be a resource count exception
Unusual user sensitive data activity@WEEKS3Minimum data points required for analysis
Unusual user sensitive data activity@THROWAWAY1When calculating averages throw away the top N%
Unusual user sensitive data activity@EVENTS10Minimum amount of events for operations exception
Unusual user sensitive data activity@SHARES10Minimum amount of shares for share activity exception
Unusual user sensitive data activity@FILES10Minimum amount of files for resource count exception
Unusual user sensitive data activity@DAYS7Amount of days to generate exceptions for from today
Unusual user sensitive data activity@EVENTSTDDEVS3Multiples of standard deviation required to be an operations exception
Unusual user sensitive data activity@GATESTDDEVS3Multiples of standard deviation required to be a share exception
Unusual user sensitive data activity@FILESTDDEVS3Multiples of standard deviation required to be a resource count exception
Ransomware@WEEKS3Minimum data points required for analysis
Ransomware@THROWAWAY1When calculating averages throw away the top N%
Ransomware@EVENTS10Minimum amount of events for operations exception
Ransomware@SHARES10Minimum amount of shares for share activity exception
Ransomware@FILES10Minimum amount of files for resource count exception
Ransomware@DAYS7Amount of days to generate exceptions for from today
Ransomware@EVENTSTDDEVS3Multiples of standard deviation required to be an operations exception
Ransomware@GATESTDDEVS3Multiples of standard deviation required to be a share exception
Ransomware@FILESTDDEVS3Multiples of standard deviation required to be a resource count exception
Unusual user stale data activity@WEEKS3Minimum data points required for analysis
Unusual user stale data activity@THROWAWAY1When calculating averages throw away the top N%
Unusual user stale data activity@EVENTS10Minimum amount of events for operations exception
Unusual user stale data activity@SHARES10Minimum amount of shares for share activity exception
Unusual user stale data activity@FILES10Minimum amount of files for resource count exception
Unusual user stale data activity@DAYS7The amount of days to generate exceptions for from today
Unusual user stale data activity@EVENTSTDDEVS3Multiples of standard deviation required to be an operations exception
Unusual user stale data activity@GATESTDDEVS3Multiples of standard deviation required to be a share exception
Unusual user stale data activity@FILESTDDEVS3Multiples of standard deviation required to be a resource count exception
Unusual user stale data activity@STALETHRESHOLD365Number of days after which resources are considered stale

See the Configure the Customizable Parameters in an Analysis Task topic for additional information on modifying analysis parameters.