Security Compliance

How to find the source event(s) in SEM from a rule triggering email alert.

This article below show on how to find the source event(s) in SEM from a rule triggering email alert.

First published date

6/16/2021 5:26 PM

Last published date

6/16/2021 5:26 PM

Overview

This article provides information and steps on how to find the source event(s) in SEM from a rule triggering email alert.
Most customers get email alerts triggering off from configured and enabled rules, but find it difficult to trace back the source event which triggers the rule. 
 

Product section

Security Event Manager

Cause

NA

Resolution

Step 1: Search for the triggered/fired rule:

  1. As per the screenshot below (1.) Got to Live Events dashboard (2.) Select Rule Activity
  2. (3.)(4.) Search for the rule name as per the email alert or the rule as per the InferenceRule in the InternalRuleFired event. And also make a note of the time you have received the email alert.
Example Rule: "Critical Account Logon Failures"
 
Security Event Manager  Live Events - "Rule Activity"e  Y FILTERS  Overview  All Events  Subscriptions  Microsoft 365  SEM Internal Events  New Unmatched Connector Data  Rule Activity 2.  Security  Incidents  Security Events  Network Event Threats  All Firewall Events  All Threat Events  Denied ACL Traffic  Unusual Network Trafic  Blocked Web Traffic  Proxy Bypassers  Web Traffic Spyware  Virus Attacks  IDS ScardAttack Activity  Events  Live Mode  NAME  InternalRuIeFired  Intern a I RuleFired  InternalRuIeFired  Internal RuleFired  InternalRuIeFired  InternalRuIeFired  Internal Rule Fired  InternalRuIeFired  InternalRuIeFired  Internal Rule Fired  InternalRuIeFired  Intern a I Rule Fired  InternalRuIeFired  InternalRuIeFired  ntS  Rules  EVENT INFO  The Critical Account Logon Failures' rule fired  The 'Crtical Account Logon Failures' r fired  The Critical Account Logon Failures' rule fired  The Critical Account Logon Failures' rule fired  The 'Critical Account Logon Failures' rule fired  The Critical Account Logon Failures' rule fired  The Account Failures' rule fired  The Critical Account Logon Failures' rule fired  The Critical Account Logon Failures' rule fired  The Crtical Account Logon Failures' rule fired  The Critical Account Logon Failures' rule fired  The Account Failures' rule fired  The 'Critical Account Logon Failures' rule fired  The Critical Account Logon Failures' rule fired  Showing all 3522 refined results from 1 OØO loaded items  CSV  Load more data  4. Critical Account Logon Failures x  2214  » DETAIL  Type to filter detæil Cat'...  Event Type  InternalRuIeAred  EventlnfO  DETECTION Ip  10.112.11.7  10.112.11.7  10.1 12.1 1.7  10.112.11.7  10.112.11.7  10.112.11.7  10.112.11.7  10.112.11.7  10.112.11.7  10.112.11.7  10.112.11.7  10.112.11.7  10.112.11.7  DETECTION TIME  2021-06-14 10:02  2021-05-14 10:02  2021-06-14 10:02  2021-06-14 10:00  2021-06-14 10:00  202106-14 10:00  202  2021-06-14 09:58  2021-06-14 og:ss  2021-06-14  202108-14 09:56  2021-06-14 09:ss  2021-06-14 og:ss  Th 'Critical Account L  Detection' P  <SEM  TOO i as  TriGeo  InsertionIP  DetectionT'  2021-06-1 10:13:  Extraneous Info  n Failures ule fired  5.  Inferred [FailedAuthentjcation]  Severity  2021-06-14  InsertionTime  2021-06-14  InferenceRule  Manager  Swi_sem

Step 2: Check the Rule definition: To find the event type(s) which triggered the rule.
(1. ) Under the Rules dashboard  (2.) Refine for the "Enabled" rule(s) (3.) Search for the rule (4.) Click on "Edit" to check for the rule definition.

Example: EventType = UserLogonFailure

 
 Security Event Manager  Rules  REFINE RESULTS  Availability  énabled  Disabled  Live Events  Historical Events Rul es  More  t Name  Critical Account Logon Failures  Feilures Administrative  All selected
 
Edit rule - "Critical Account Logon Failures"  Rule definition  Details and actions  RULE VALUES  Search...  Events  b Event  Rule is true when  UserLogonEaiIure estinationAccount is in  Admin Accounts  And Whole rule  in 30  in S min

Step 3: Search the source event(s): 
  • Go to Historical Events tab and (1.) Select the period the email alert or InferenceRuleFired event occurred (2.) Now create a search query and search for the event around the same time the event got triggered.
Security Event Manager  Dashboard  Live Events  Historical Events  Historical Events  AVAILABLE FIELDS  Refine fields  Eve n tType  Event' n fo  IPAddress  prm,iderSlD  TOOIAI  u SerName  2.  1300  Export  10:13  Rules  in  3.  UserLogonFaiIure  Eve-inf. Sup;æ;  2021-06-1410:1 3:49  UserLogonFaiIure  lure  userLogonFäiIure  Configure •  10 1350  2021-06-14  2021-05-1.  F' Detuti071P-_ SUPPER  2021-08-141 c:' s:" Manager  F' 'lure Win%æ,  PruSderSJD: SZS De-stutionkæ.ntTy;e:  EVENT DETAILS  in  Event Type  UserLogonFaiIure  Even unfo  Logon Failure "DINNERibiIIybob"  DetectionIP  SLJ  TOO IA  Windows Security  ProviderslD  Security 529  Logon Process  user32  I nsertionTime  2021-0614  Manager  DetectionTime  2021-08-14  DestinationAccount  biliy&aö  DestinationMachine