Documentation Center
AlienVault® USM Anywhere™

Searching System Events

Role Availability Read-Only Analyst   Manager

USM Anywhere includes several filters displayed by default. These filters enable you to search for your items of interest. You can either filter your search, or enter what you are looking for in the search box, which is in the upper left corner of the page.

You can configure more filters and change which filters are displayed by clicking the Configure filters link, which is located in the upper left corner of the page.

Note: The management of filters is similar to that for assets. See Managing Filters for more information.

Filters displayed by default in the main System Events page
Filter Name Meaning
Created during Filter system eventsAny traffic or data exchange detected by AlienVault products through a Sensor, or through external devices such as a firewall. triggered in the last hour, last 24 hours, last 7 days, last 30 days, or last 90 days. You can also configure your own period of time by clicking the icon. This option enables you to customize a range and narrow it to delimit your search per minutes and seconds.
Suppressed

Filter suppressed system events. See Suppressing/Unsuppressing Events for more information.

Not Suppressed Filter hiding suppressed system events. The suppressed system events are hidden by default.
Event Name Filter system events by the short, user-readable description of the system event.
Source User Email Filter system events by the email of the user that performed the action. For example, when user [email protected] logs in, the source email is [email protected].
Destination User Email Filter system events by the email of the user that the action is being performed on. For example, if user [email protected] modifies or creates user [email protected], then the destination email is [email protected].
Event Outcome Filter system events by the success of an action.
Event Change Filter system events by the description of what was changed in the system event.

The number between brackets displayed by each filter indicates the number of items that matches the filter. You can also use the filter controls to provide a method of organizing your search and filtered results. These are the icons next to each filter title:

Icons next to the filter title
Sort the filters alphabetically.
Sort the filters by number of items that matches them.

In the upper left side of the page, you can see any filters you have applied. Remove filters by clicking the icon next to the filter. Or clear all filters by clicking Reset All Filters.

Note: When applying filters, the search uses the logical AND operator if the used filters are different. However, when the filter is of the same type, the search uses the logical OR.

Those filters that have more than ten options include a Filter Value search box for writing text and make the search easier.

USM Anywhere enables you to toggle the mode of search. The available modes are Standard and Advanced. You can change from one mode to the other by clicking the icon or clicking the icon located in the upper left corner of the page.

Standard Mode

This mode enables you to select one value per filter at the same time, and then the search is automatically performed. This mode is ON by default.

To activate the Standard Mode when the Advanced Mode is ON

  1. Go to Settings > System Events.
  2. In the upper left corner of the page, click the icon.
  3. Note: If you exit the advanced mode and the selected filters are not compatible with the Standard Mode, a warning popup window displays to inform you the current filters will be removed.

Advanced Mode

Advanced Mode enables you to select more than one value per filter at the same time. This mode is OFF by default.

To activate the Advanced Mode

  1. Go to Settings > System Events.
  2. In the upper left corner of the page, click the icon to active the advanced mode. This turns the icon green.

To perform a search in the Advanced Mode

  1. Go to Settings > System Events.
  2. In the upper left corner of the page, click the icon to active the advanced mode. This turns the icon green.
  3. Click the filters that you want to select.
  4. In the lower left corner of the page, click Apply Filters.
  5. Click Apply Filters Button to execute a search

    The result of your search displays.

To search using the operator NOT

  1. Go to Settings > System Events.
  2. In the upper left corner of the page, click the icon to activate the Advanced Mode.
  3. Click the filter that you want to exclude.
  4. In the filter group, click Not .
  5. Important: This operator is not available when you have selected the title.

    Note: The selected filter displays this icon and the filter chiclet is labeled in red.

To search all values of a filter

  1. Go to Settings > System Events.
  2. In the upper left corner of the page, click the icon to activate the Advanced Mode.
  3. Select a filter title to select all filters below that title.

Searching System Events by Using the Search Box

To search System Events using the search box

  1. Go to Settings > System Events.
  2. Enter your search in the Enter search phrase box.
  3. If you want to search for an exact phrase having two or more words, you need to put quotation marks around the words in the phrase.

    Note: Keep in mind that wildcard characters are considered as literals.

  4. Click the icon.
  5. The result of your search displays with the items identified.