Skip to main content
Version: 5.0

Account Management

Description

The Identity and Access Management section is designed for monitoring events related to the management of user accounts (AM), groups, and workstations.

Displayed Data

  • Statistics on the number of created / modified / deleted AM
  • Trends in the number of created / modified / deleted AM
  • Event statistics with details on user AM
  • Event statistics with details on group AM
  • Event statistics with details on workstation AM

List of Dashboards

  • Account Management: Overview
  • Account Management: Groups
  • Account Management: Computers
  • Account Management: Users

Data Model

The section uses the following fields from data sources. Alias used: sm_cs_iam_indexes.

Data Model

The section uses the following fields from data sources. Alias used: sm_cs_iam_indexes.

Categorization Fields

Field NameValue
event.kindevent
event.categoryiam
event.typecreation | deletion | change
event.outcomesuccess | failure | unknown
event.actionFrom the original event.
event.codeWindows Security Event code from the original event.

General Purpose Fields

Information System event

Field NameValue
event.moduleModule name.
event.datasetDataset name.

User user

Field NameValue
user.nameUsername.
user.domainUser domain.
user.idUser Security Identifier (SID).

Host Information host

Field NameValue
host.nameHost name.

Information about the AM on which the action is performed target

Field NameValue
target.nameUsername.
target.domainUser domain.
target.idUser Security Identifier (SID).

Other Fields

Field NameValue
event.originalOriginal event text.

Reference Tables

Below is a table of reference tables used in the section.

NameFieldsDescription
sm_cs_iam_privileged_users_lookupaccount.name
is_privileged
Reference table for privileged AM values.

Example Sources