Event Monitoring

NAVIGATION  General > Event Monitoring

SaaS Alerts provides constant monitoring and robust AI-driven intelligence that detects security threat events and raises alerts in real time. Refer to Getting started with SaaS Alerts to learn how to configure SaaS applications and start analyzing alerts.

You can filter your alerts by keyword, customer, product, IP/location, and description.

Critical, medium, and low alerts

View the most recent critical, medium, and low alerts. The list of the last 100 alerts is updated every 60 seconds. You can filter the results using the drop-down menus at the top of the page.
2024-06-04 10_14_28-.png

Suppressed alerts

Search and view alerts that are suppressed. You can also view when a suppression expires as well as release a suppression.
2024-06-04 10_45_45-.png

Alert types

Critical

Critical alerts require immediate attention and communication with the customer.

  • IAM Event - User Location - Outside approved location 
  • Policy Event - Admin Access Granted 
  • IAM Event - Multiple Password Reset 
  • Policy Event -  Security Policy Change 
  • IAM Event - Multiple Account Locks 
  • Unable to Refresh SaaS App Token 
  • Policy Event - Admin Access Granted 

Standard

A standard alert requires evaluation on the part of the MSP and a decision on what step to take next with the customer.

  • IAM Event - Account Locked
  • IAM Event - Multiple Authentication Failures
  • Device Event - New Device
  • Policy Event - Security Group Change

Logged event

The following are examples of a logged event:

  • IAM Event - Authentication Failure
  • IAM Event - Authentication Success
  • Application Integration Detail - SaaS Application File Share
  • IAM Event - Oauth Access Used for Foreign Application
  • File Share Event - Internal
  • File Share Event - External
  • File Share Event - Local Download
  • File Share Event - External Orphaned Link
  • Application Integration Detail - SaaS Application Link Share
  • IAM Event - Password Reset
  • IAM Event - Multiple Login Connections From Different IP Addresses
  • IAM Event - Multiple SaaS Connections From Different IP Addresses
  • IAM Event - New User Added
  • IAM Event - An Unknown Actor is Attempting to Access the Domain