Optimizations
- Last Updated: September 16, 2026
- 2 minute read
- Flowmon Products
- Flowmon Anomaly Detection System
- Documentation
The Optimizations page contains suggestions for improving your Flowmon ADS configuration to reduce the amount of false positive detections.
Filters
This page helps you optimize your Flowmon ADS configuration by identifying source IP addresses that generate a higher than minimal number of events. Refer to the Scanning section for further details. Each suggestion item contains an IP address and a filter to which the IP address can be added so that it is no longer detected by specific methods.
Optimization suggestions are recomputed daily at nighttime, based on events from the last seven days. When a number of events greater than threshold is detected for an IP address by a detection‑method instance, an optimization suggestion is created. Once the optimization is approved and applied, the IP address is added to the suggested filter.
In the Pending tab, you can review optimization suggestions that are waiting for your decision. Mark optimizations as approved or declined, then click Apply Optimizations to submit your approved and declined decisions. Always thoroughly review the suggestions before accepting them as it will affect further detection (for example, "are these really false positives caused by legitimate DNS server that was not added to suggested filter?"). To facilitate the investigation, there is a context menu and "show related events" action, you may also open the FMC and analyze the IP communications (flows).
The Processed tab shows all previously processed optimizations with their approval status and notes. Use filters to search by IP address, detection method, or decision type (approved/declined).
Notes you add to optimizations are visible in the Processed tab and will also appear as IP comments inside the filter if the optimization is approved.
The Delete data action also deletes all optimization suggestions.
Settings
Scanning
The Scanning section of Optimizations Settings allows you to enable/disable the optimization suggestions (disabling the feature will prevent further daily recomputes, but it will not delete the existing suggestions).
You may also specify the minimal number of events required to trigger an optimization suggestion for an IP address. Setting a higher threshold will result in fewer suggestions, while a lower threshold may generate more suggestions, including those that may not be significant.
Whenever you enable the optimizations after they have been previously disabled, the Save and recompute button may be used to trigger an immediate recompute.
To receive proper recommendations, you must assign filters to the relevant parameters of detection methods (for example, the ExcludeServers parameter of the HIGHTRANSF method). These parameters may be undefined by default. To create the required filters and populate the parameters, complete the related steps in the Configuration wizard.