Delinea - Events by severity
Breaks down the Delinea Platform audit stream by event severity / level (e.g. PrivilegedActivity, Info, Warning, Error) over the lookback window, with no alerting threshold applied. Shows the event count, distinct…
Description
Breaks down the Delinea Platform audit stream by event severity / level (e.g. PrivilegedActivity, Info, Warning, Error) over the lookback window, with no alerting threshold applied. Shows the event count, distinct users, and the top event types contributing to each level so an analyst can gauge the overall mix of activity and zero in on the higher-severity tiers. Use it to spot an unusual spike of privileged or error-level events relative to normal volume.
Detection logic
Detection requirements
- Platform
- ESXiIaaSIdentity ProviderLinuxmacOSOffice SuiteSaaSWindows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
- Log source product
- delineaplatformconnector
- Log source service
- delineaauditevents_cl
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
No references are available for this detection.
From the source
- At source
- Open at source
- Upstream identifier
- e9850d1c-4821-4375-bfe7-3559684c141d
- Tagged by the source as
- Discovery
Licence
- Published under
- MIT LicenseRead the licence
- Attribution
- Required
- Obtained under
- MITRead the origin licence
Authorship
- Published
- Oct 7, 2026
- Version
- 1