Security Compliance

SEM All Threat Events filter conditions

This article shows the default conditions used for the All Threat Events filter under the Security section.

First published date

10/31/2018 7:03 PM

Last published date

2/20/2025 1:11 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).

This article provides the default conditions used for the All Threat Events filter under the Security section.

Product section

Security Event Manager

Resolution

Name: All Threat Events

Conditions:
(OR)1st group{

(AND)2nd group{Asset Scan Result Alerts.IsThreat == True}

(AND)3rd group{Auth Audit Alerts.IsThreat == True}

(AND)4th group{Auth Suspicious Alerts.IsThreat == True}

(AND)5th group{HostIncident.IsThreat == True}

(AND)6th group{HybridIncident.IsThreat == True}

(AND)7th group{Network Attack Alerts.IsThreat == True}

(AND)8th group{Network Audit Alerts.IsThreat == True}

(AND)9th group{NetworkIncident.IsThreat == True}

(AND)10th group{Network Suspicious Alerts.IsThreat == True}

(AND)11th group{Policy Access Alerts.IsThreat == True}

(AND)12th group{VirusAttack.IsThreat == True} }

 

See the Default SEM filter conditions on the Web Console Monitor page  page article for a full list of available default filters in SEM.