User activity data
A user activity data record is a security event type that
-
logs the appearance and login of users on a network,
-
enables correlation between user actions and other network events such as intrusions, and
-
supports automated remediation and alerting through customizable rules.
The system generates events that communicate the details of user activity on your network. When the system detects user activity, the user activity data is logged to the database. You can view, search, and delete user activity; you can also purge all user activity from the database.
The system logs a user activity event when a user is seen on your network for the first time. Subsequent appearances by that user do not log new user activity events. However, if the user's IP address changes, the system logs a new user activity event.
The system also correlates user activity with other types of events. For example, intrusion events can tell you the users who were logged into the source and destination hosts at the time of the event. This correlation can tell you who was logged into the host that was targeted by an attack, or who initiated an internal attack or portscan.
You can also use user activity in correlation rules. Based on the type of user activity as well as other criteria that you specify, you can build correlation rules that, when used in a correlation policy, launch remediations and alert responses when network traffic meets your criteria.
Note | If you have ISE/ISE-PIC configured, you may see host data in the users table. Because host detection by ISE/ISE-PIC is not fully supported, you cannot perform user control using ISE-reported host data. |
Descriptions of the four types of user activity data follow.
New User Identity
This type of event is generated when the system detects a login by an unknown user that is not in the database.
The system logs a user activity event when a user is seen on your network for the first time. Subsequent appearances by that user do not log new user activity events. However, if the user's IP address changes, the system logs a new user activity event.
User Login
This type of event is generated when any of the following occur:
-
Captive portal performs a successful or failed user authentication.
-
Traffic-based detection detects a successful or failed user login.
Note | SMTP logins detected by traffic-based detection are not recorded unless there is already a user with a matching email address in the database. |
When a non-authoritative user logs into a host, that login is recorded in the user and host history. If no authoritative user is associated with the host, a non-authoritative user can be the current user for the host. However, after an authoritative user logs into the host, only a login by another authoritative user changes the current user.
If you are using captive portal or traffic-based detection, note the following about failed user login and failed user authentication data:
-
Failed logins reported by traffic-based detection (LDAP, IMAP, FTP, and POP3 traffic) are displayed in the table view of user activity, but not in the table view of users. If a known user failed to log in, the system identifies them by their username. If an unknown user failed to log in, the system uses Failed Authentication as their username.
-
Failed authentications reported by captive portal are displayed in both the table view of user activity and the table view of users. If a known user failed to authenticate, the system identifies them by their username. If an unknown user failed to authenticate, the system identifies them by the username they entered.
Delete User Identity
This type of event is generated when you manually delete a user from the database.
User Identity Dropped: User Limit Reached
This type of event is generated when the system detects a user that is not in the database, but cannot add the user because you have reached the maximum number of users in the database as determined by your Cloud-Delivered Firewall Management Center model.
After you reach the user limit, in most cases the system stops adding new users to the database. To add new users, you must either manually delete old or inactive users from the database, or purge all users from the database.
However, the system favors authoritative users. If you have reached the limit and the system detects a login for a previously undetected authoritative user, the system deletes the non-authoritative user who has remained inactive for the longest time, and replaces it with the new authoritative user.
User Indications of Compromise Events
The following user IOC changes are logged in the user activity database:
-
When indications of compromise are resolved.
-
When indication of compromise rules are enabled or disabled for users.
For information about general user-related event troubleshooting, refer to Troubleshoot realms and user downloads.