SOLVED

Created Policy - What is the difference: Alerts vs Activity?

%3CLINGO-SUB%20id%3D%22lingo-sub-1703849%22%20slang%3D%22en-US%22%3ECreated%20Policy%20-%20What%20is%20the%20difference%3A%20Alerts%20vs%20Activity%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1703849%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20created%20a%20policy%20for%20Failed%20Log%20on%20and%20when%20I%20check%20my%20alerts%2C%20I%20see%2010.%26nbsp%3B%20But%20when%20I%20look%20at%20the%20activity%20log%20and%20run%20the%20query%20based%20off%20of%20the%20policy%20I%20created%2C%20there%20are%20over%205%2C000.%26nbsp%3B%20Additionally%2C%20when%20I%20search%20for%20one%20of%20the%20Alerts%20in%20the%20activity%20log%2C%20I'm%20unable%20to%20find%20that%20action.%26nbsp%3B%20I%20would%20think%20all%20of%20the%2010%20Alerts%20should%20be%20found%20in%20the%20Activity%20log.%26nbsp%3B%20Please%20help%20with%20the%20understanding%20of%20the%20difference.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%2C%3C%2FP%3E%3CP%3ESerge%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1703849%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECloud%20App%20Security%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EThreat%20Protection%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1708211%22%20slang%3D%22en-US%22%3ERe%3A%20Created%20Policy%20-%20What%20is%20the%20difference%3A%20Alerts%20vs%20Activity%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1708211%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616520%22%20target%3D%22_blank%22%3E%40SergioT1228%3C%2FA%3E%26nbsp%3BGreat%20question!%20The%20activity%20log%20will%20be%20a%20view%20of%20all%20the%20activities%20performed%20in%20your%20connected%20applications.%20This%20could%20range%20from%20a%20log%20on%2C%20file%20download%2C%20task%20creation%2C%20etc%20where%20as%20an%20alert%20will%20notify%20you%20of%20a%20potential%20threat%20in%20your%20cloud%20environment.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20reason%20why%20you%20may%20be%20seeing%20more%20failed%20log%20ons%20in%20activity%20log%20vs.%20in%20the%20alert%20panel%20is%20because%20sometimes%20failed%20logins%20can%20be%20normal%20behavior%20(i.e.%20user%20forgetting%20their%20password).%20This%20could%20also%20depend%20on%20how%20you've%20scoped%20your%20policy%20i.e.%20alert%20on%2010%20repeated%20failed%20log-ons%20in%20a%205%20min%20time%20interval%20would%20only%20result%20in%201%20alert%20but%2010%20entries%20in%20activity%20log.%20There%20is%20also%20specific%20anomaly%20detection%20policy%20based%20off%20of%20User%20Entity%20Behavior%20Analytics%20(UEBA)%2C%20where%20MCAS%20studies%20the%20behavior%20of%20the%20user%20for%207%20days%20and%20establishes%20a%20baseline%20for%20each%20user%20and%20will%20alert%20on%20any%20unusual%20behavior.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EInvestigating%20multiple%20failed%20logon%20attempts%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcloud-app-security%2Finvestigate-anomaly-alerts%23multiple-failed-login-attempts%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcloud-app-security%2Finvestigate-anomaly-alerts%23multiple-failed-login-attempts%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EActivities%20in%20MCAS%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcloud-app-security%2Factivity-filters%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcloud-app-security%2Factivity-filters%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EDoes%20that%20answer%20your%20question%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

I have created a policy for Failed Log on and when I check my alerts, I see 10.  But when I look at the activity log and run the query based off of the policy I created, there are over 5,000.  Additionally, when I search for one of the Alerts in the activity log, I'm unable to find that action.  I would think all of the 10 Alerts should be found in the Activity log.  Please help with the understanding of the difference.

 

Cheers,

Serge

1 Reply
best response confirmed by SergioT1228 (Occasional Contributor)
Solution

@SergioT1228 Great question! The activity log will be a view of all the activities performed in your connected applications. This could range from a log on, file download, task creation, etc where as an alert will notify you of a potential threat in your cloud environment.

 

The reason why you may be seeing more failed log ons in activity log vs. in the alert panel is because sometimes failed logins can be normal behavior (i.e. user forgetting their password). This could also depend on how you've scoped your policy i.e. alert on 10 repeated failed log-ons in a 5 min time interval would only result in 1 alert but 10 entries in activity log. There is also specific anomaly detection policy based off of User Entity Behavior Analytics (UEBA), where MCAS studies the behavior of the user for 7 days and establishes a baseline for each user and will alert on any unusual behavior. 

 

Investigating multiple failed logon attempts: https://docs.microsoft.com/en-us/cloud-app-security/investigate-anomaly-alerts#multiple-failed-login...

Activities in MCAS: https://docs.microsoft.com/en-us/cloud-app-security/activity-filters

 

Does that answer your question?