Set the parameters according to which users are placed in quarantine.
First review your current alerts before deciding on the best way to identify a user in your network. The best option is when one parameter is always unique in your network. For example, terminal is unique in some networks, but it is not used in others.
On the System page, click the Quarantine tab.
Click Settings and select or deselect the checkboxes for the parameters that define when a user can be quarantined.
The system applies the operator "and" to the selected parameters.
For example, if you select User and IP address, when triggered by a rule, the system checks the user name and the IP address (for example, Scott and 192.168.7.7). The system denies access to any subsequent SQL statements that comes from 192.168.7.7 and the user Scott. Statements coming from 192.168.7.7 where the user Jerry is allowed.
Click Save.