Skip to main content
Version: 6.0

Account Management

Description​

The Identity and Access Management section is designed for monitoring events related to the management of user accounts (AM), groups, and workstations.

Displayed Data​

  • Statistics on the number of created / modified / deleted AM
  • Trends in the number of created / modified / deleted AM
  • Event statistics with details on user AM
  • Event statistics with details on group AM
  • Event statistics with details on workstation AM

List of Dashboards​

  • Account Management: Overview
  • Account Management: Groups
  • Account Management: Computers
  • Account Management: Users

Data Model​

The section uses the following fields from data sources. Alias used: sm_cs_iam_indexes.

Data Model​

The section uses the following fields from data sources. Alias used: sm_cs_iam_indexes.

Categorization Fields​

Field NameValue
event.kindevent
event.categoryiam
event.typecreation | deletion | change
event.outcomesuccess | failure | unknown
event.actionFrom the original event.
event.codeWindows Security Event code from the original event.

General Purpose Fields​

Information System event​

Field NameValue
event.moduleModule name.
event.datasetDataset name.

User user​

Field NameValue
user.nameUsername.
user.domainUser domain.
user.idUser Security Identifier (SID).

Host Information host​

Field NameValue
host.nameHost name.

Information about the AM on which the action is performed target​

Field NameValue
target.nameUsername.
target.domainUser domain.
target.idUser Security Identifier (SID).

Other Fields​

Field NameValue
event.originalOriginal event text.

Reference Tables​

Below is a table of reference tables used in the section.

NameFieldsDescription
sm_cs_iam_privileged_users_lookupaccount.name
is_privileged
Reference table for privileged AM values.

Example Sources​