![]() |
Unmatched events are events that pass through the system transparently, because they raise no suspicion.
|
![]() |
Policy matches are events that are analyzed as they traverse the system, because something in the transaction is suspicious according to the policies. Policy matches are then either deemed authorized incidents—events that seemed to match a policy but are in fact allowed—or incidents, which are policy violations.
|