From the Attack Log, you can manually quarantine hosts. To quarantine hosts from Attack Log, you must enable Quarantine on the corresponding inline monitoring ports. Quarantine from Attack Log has no relation to enabling it in the attack definitions. You can also add IP addresses to quarantine from the Quarantine page.
Note
If the source IP is behind a proxy server, the proxy server IP is quarantined. Consequently, all traffic through the proxy server gets quarantined.