Security Compliance
How to find the source event(s) in SEM from a rule triggering email alert.
This article below show on how to find the source event(s) in SEM from a rule triggering email alert.
First published date
Last published date
Overview
Most customers get email alerts triggering off from configured and enabled rules, but find it difficult to trace back the source event which triggers the rule.
Product section
Cause
Resolution
Step 1: Search for the triggered/fired rule:
- As per the screenshot below (1.) Got to Live Events dashboard (2.) Select Rule Activity
- (3.)(4.) Search for the rule name as per the email alert or the rule as per the InferenceRule in the InternalRuleFired event. And also make a note of the time you have received the email alert.
Step 2: Check the Rule definition: To find the event type(s) which triggered the rule.
Example: EventType = UserLogonFailure
Step 3: Search the source event(s):
- Go to Historical Events tab and (1.) Select the period the email alert or InferenceRuleFired event occurred (2.) Now create a search query and search for the event around the same time the event got triggered.