Watchlist 编辑

Use watchlists to monitor the activity of specific users for potential threats. For example, you can monitor users who are not full-time employees in your organization or users who trigger a specific risk indicator frequently.

How to add a user to the watchlist

You can either add a user to the watchlist manually, or you can define policies that when triggered adds a user to the watchlist.

To add a user to the watchlist manually, navigate to the user’s profile on the risk timeline. Then, from the Actions menu, select Add to watchlist. Click Apply and follow the prompts to enforce the action.

Action to add to watchlist

To add a user to the watchlist using policies, create a policy with a set of conditions that must be met. Select the Add to watchlist action. When the conditions are met, the user is added to the watchlist. For example, you might want to add a user to the watchlist if the user’s risk score change is greater than 70 in 30 minutes.

For more information about creating policies, see Configure policies and actions.

Policy to add to watchlist

How to remove a user from the watchlist

You can either remove a user from the watchlist manually, or you can define policies that when triggered removes a user from the watchlist.

To remove a user from the watchlist manually, navigate to the user’s profile on the risk timeline. Then, from the Actions menu, select Remove from watchlist. Click Apply and follow the prompts to enforce the action.

Note

When a user is on the watchlist, and you want to remove them, you see the Remove from watchlist option in the Actions menu.

Action to remove from watchlist

To remove a user to the watchlist using policies, create a policy with a set of conditions that must be met. Select the Remove from watchlist action. When the conditions are met, the user is removed from the watchlist. For example, you might want to remove a user from the watchlist if the user’s risk score change is lesser than 70 in 60 minutes. To learn more about creating policies, see Configure policies and actions.

Policy to remove from watchlist

How to monitor users in a watchlist

On the Security > Users dashboard, view the following:

  • Summary of the number of users in the watchlist for the last 13 months. Click the box to view the list of all users in the watchlist on the Users in Watchlist pane.

  • Top five users in the watchlist listed based on the risk score. In the Users in Watchlist pane, view the risk score, and risk indicator occurrences along with the name of the user. Click See More to view the list of all users in the watchlist on the Users page.

  • Top risky users who are in the watchlist. In the Risky Users pane, the “eye” icon next to a user indicates that the user is in the watchlist.

Users dashboard users in watchlist

On the Users page, view the list of all users in the watchlist. View details such as the risk score, number of risk indicators triggered, and associated data sources for a user.

Use the search box to find users and their event details. Select the time period to view the risk indicator occurrences for the specific period.

Users watchlist page

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。
列表为空,暂无数据

词条统计

浏览:82 次

字数:4978

最后编辑:7 年前

编辑次数:0 次

    我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
    原文