USM Anywhere™

USM Anywhere System Events List View

Role Availability Read-Only Analyst   Manager

AlienVault USM Anywhere provides a centralized view of your system events Any traffic or data exchange detected by AT&T Cybersecurity products through a sensor, or through external devices such as a firewall.. Go to Settings > System Events.

The system events page displays information on any events generated within your environment. On the left you can find the search and filters options. In the upper side of the page, you can see any filters you have applied, and you have the option to create and select different views of the system events. The main part of the page is the actual list of system events. Each row describes an individual system event.

If you want to analyze the data, you can maximize the screen and hide the filter pane. Click the icon to hide the filter pane. Click the icon to expand the filter pane.

Note: By default, the list will display all System Events created during the last 24 hours.

List of the default columns in Events
Column Field Name Description
Event Name Name of the event.
Time Created The date and time of the creation of the event. The displayed date depends on your computer's time zone.
Source User Email Email of the user that performed the action. For example, when user logs in, the source email is
Destination User Email Email of the user that the action is being performed on. For example, if user modifies or creates user, then the destination email is
Event Outcome Indicates if the action was success and completed or if it failed.
Event Change

It is a small description of what was changed in the system event.

It only gets populated for certain actions and indicates what is being changed. Most of these are user changes. For example, when a user is suspended, locked status is reset, MFA A method of access control in which a user is granted access only after successfully presenting several separate pieces of evidence to an authentication mechanism – typically at least two of the following categories: knowledge, possession, and inherence. is enabled/disabled, or password updated

Identity Source Address IP address of the event or computer that it takes place on.

Click the icon to bookmark an item for quick access. Clicking the icon on the secondary menu shows the bookmarked items and provides links to them.

You can choose the number of items to display by selecting 20, 50, or 100 below the table. You can classify some columns by clicking the icons to the right side of the heading. You can sort the item information in ascending or descending order.


USM Anywhere enables you to define and save a custom System Events view to have your own selected filters.

To create a view configuration

  1. Go to Settings > System Events.
  2. If you want to delimit the search, select the filters you want to apply.
  3. Select Save View > Save as.

    Views dialog vox

  4. Enter a name for the view.
  5. Select Share View if you want to share your view with other users.
  6. Click Save.
  7. The created view is already selected.

To select a configured view

  1. From the System Events list view, click View above the filters.
  2. Click Saved views and select the view you want to see.
  3. Note: A shared view includes the icon next to its name.

  4. Click Apply.

To delete a configured view

  1. From the System Events list view, click View above the filters.
  2. Click Saved views and click the icon next to the saved view you want to delete.
  3. A dialog box displays to confirm the deletion.

    Note: You can delete the views you have created.

  4. Click Accept.
  5. Important: The icon does not display if the view is selected.