When the normal threshold is set to maximum, the machine learning system will not generate attacks based on that variable. All other variables continue to operate in either system or user mode.

You can also disable or enable an attack ID globally by using the attackstatus REST API. For more information, see Enabling or disabling attack IDs.