Detect anomalous traffic
When a traffic anomaly alert fires, analyzes traffic patterns for unusual spikes, geographic anomalies, suspicious request patterns, and potential DDoS indicators. Checks for unusual user-agent strings, abnormal request rates from specific IPs, and unexpected API endpoint usage. Correlates with authentication logs to identify potential credential stuffing or brute force attempts.
Install
Create this automation from the CLI, or pick it in the console under Automations → New → From template.
polylane automation from-template detect-anomalous-trafficTrigger
The event that starts this automation.
Fires every time a connected observability provider sends an alert webhook to Polylane.
Compatible providers
2Integrations this automation investigates and uses tools from. Connect them to unlock the full workflow.
Skills
2These skills are installed automatically when you create this automation.
Actions
1Platform-executed side effects the agent can request. These are applied when you create this automation.
Agent instructions
The prompt the agent follows on each execution. Customize it to fit your team's playbook.
Parallel passes
How it works
When a alert event occurs, an agent runs the instructions above, investigating with your connected Datadog, AWS tools, and sends results to your configured destinations.
Destinations
When you create this automation your email is added as a destination, so every run lands in your inbox. Add chat or webhook destinations afterward.