Security Compliance

SEM rule for when users connect to a specific website

This article provides information about the SEM Rules when a user connects to a specific website.

First published date

10/12/2018 7:57 PM

Last published date

3/28/2019 5:32 PM

Overview

This article provides information about the Security Event Manager (formerly Log & Event Manager) rules when a user connects to a specific website.

Product section

Security Event Manager

Resolution

Perform an nDepth query for the following criteria:

WebTrafficAudit.URL CONTAINS /ENTER_URL_HERE/
  1. On SEM console toolbar, navigate to Explore > nDepth.
  2. In the list pane, expand the Events category, and then search for webtrafficaudit.
  3. Under Fields: WebTrafficAudit, locate the URL field and drag it into the Conditions box.
  4. Enter the URL, and then click the search button. 


    If this returns the expected results, build a new rule and set the correlation to the same as the above. Specify a correlation time and appropriate action. Find out how to build a new rule here.



To check the WebTrafficAudit: 

Go to ResourceAudit > NetworkAudit > ApplicationTrafficAudit > WebTrafficAudit.

WebTrafficAudit alerts reflect application-layer data related to web services. Included in WebTrafficAudit are client and server web events from web servers, web applications, content filter related events, and other web services.

WebTrafficAudit alerts generally indicate normal traffic, however, alerts of this type could also be symptoms of inappropriate web usage, potential abuse of web services, or other abnormal traffic.