Back to results

Delinea - Events by severity

Breaks down the Delinea Platform audit stream by event severity / level (e.g. PrivilegedActivity, Info, Warning, Error) over the lookback window, with no alerting threshold applied. Shows the event count, distinct…

Description

Breaks down the Delinea Platform audit stream by event severity / level (e.g. PrivilegedActivity, Info, Warning, Error) over the lookback window, with no alerting threshold applied. Shows the event count, distinct users, and the top event types contributing to each level so an analyst can gauge the overall mix of activity and zero in on the higher-severity tiers. Use it to spot an unusual spike of privileged or error-level events relative to normal volume.

Detection logic

Detection requirements

Platform
ESXiIaaSIdentity ProviderLinuxmacOSOffice SuiteSaaSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Log source product
delineaplatformconnector
Log source service
delineaauditevents_cl

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice