User activity monitoring

Using the User activity monitoring tab, administrators can customize the IOBs (modify the IoB predefined severity and exclude or include certain users and groups).

User activity monitoring tab

This view displays the following columns:

1
IOB No: Every IoB has a unique identification number icon is to show the modified IoB. This icon indicates the modified IoB.
2
Rule name: Associated rule that is matched when a specific user activity is observed.
3
Status: Indicates whether the IoB is enabled or disabled.
4
Severity: Informative, Low, Medium, High, Critical, Dynamic.
5
Category: Indicates the nature of the security threat.
6
Channel: Indicates whether the activity happened on web, any system modifications etc.
7
Description: Specifies the suspicious behavior or user activity.
8
User exceptions: Indicate the user or groups that are exempted from monitoring for the specific behavior.

Filtering capability allows for filtering based on a specific column in the User activity monitoring tab. On mouse over the column this icon is displayed. Click the icon to filter on the selected column.