Software Secure Workload
Activity Configure

Run Policy Experiments to Test Current Policies Against Past Traffic

If a known attack or other significant short-term traffic pattern occurred in the past, and you want to see how your current policies (or another versioned policy set) would have handled that traffic, you can use the Run Experiments feature.

Before you begin


 

As an alternative to this procedure, you can run automatic policy discovery again, including the relevant time range, and see what different policies are suggested.

Procedure

1

Navigate to the Policy Analysis page of your selected workspace.

2

From the top of the page, select the policy version to test.

3

Click Run Experiment.

4

Enter a name and a duration for the policy experiment.

Run Experiment Form
Figure 1: Run Experiment Form

This will start a new policy analysis job which goes back in time and re-analyzes all the flows in the selected duration against the selected versioned policy.

This job may take a few minutes, depending on the selected duration. The progress is shown in the policy selector menu. When the results are ready to be presented, you should be able to select the policy experiment like any other versioned policy and the time series charts showing different flow categories will be updated accordingly.

Experiment
Figure 2: View Experiment Status

 

If you cannot see any flows when selecting a policy experiment, it might be due to time range mismatch, for example, the current time range of the charts is the past 1 hour, but the experiment duration is 6 hours in the past. To reset the time range to the duration of the experiment, click the clock icon next to the policy selector.

Match time range
Figure 3: Match Time Range