All Collections
For CORE Admins
Security & Suspicious Activity
Suspicious Activity Overview & Monitoring
Suspicious Activity Overview & Monitoring
Updated over a week ago

CORE constantly monitors all activity for suspicious behavior, and logs anything it finds. The Suspicious Activity page allows Admins the ability to see all requests made to the system which have been flagged as suspicious.

In this article:

Screen_Shot_2022-01-07_at_6.33.54_PM.png
Screen_Shot_2022-01-07_at_6.36.32_PM.png

Filters

Use these filters to view an activity report based on a date range, specific User, or specific security issue.

Screen_Shot_2022-01-07_at_6.37.12_PM.png

Date Range

Add a Start and End Date to the Date Range to filter the report by inputs within that range.

User

Use this dropdown to view only inputs from a specific User. You can type in this field to search for names. Click the button to clear it.

Security Issue

Use this dropdown to view only inputs of a specific Security Issue type. You can type in this field to search for Issue types. Click the button to clear it.


Suspicious Activity Report

View the results of the report here.

Screen_Shot_2022-01-07_at_6.38.17_PM.png

Report Fields

  1. userInput - This field shows the request made by the User. Click the red arrow ➧ icon to expand this and view the full request, as well as the Filter Match from the system, which is the portion of the request that was flagged as a security issue.

  2. userId - The internal ID # of the User who made the request.

  3. idsId - The internal ID # of the issue found by the CORE Intrusion Detection System.

  4. idsDescription - The description of the issue found by the CORE Intrusion Detection System.

  5. tags - The category or categories of the issue.

  6. impact - The severity of the issue, on a scale from 1-7.

  7. message - The message from the Intrusion Detection System regarding the issue found.

  8. type - The type of issue found.

  9. user - The Username of the User who made the request.

  10. eventTime - The time the request was made.

Did this answer your question?