SCC Help >> FAQ

FAQ

Why the actions described by Correlated Policy on the Browse Attack Alarm page are inconsistent with the actions described by Result on this page?

It is because the corresponding policy of the alarm has been modified. There should be an alert on the result report page, saying "Policy was modified and action history cannot be found."

Why the action failed when UAM worked with the SCC to log off or isolate online users?

By default, the system must wait 120 seconds before it can perform the same action (log off or isolate) again on an user identified by IP or MAC address. UAM cannot work with SCC to process the user if it logs online again within this period.