Daily Host Alerts

by David Schwalenberg
December 4, 2013

The LCE event Daily_Host_Alert generates, once per day, an alert the first time an event from a local host (such as a DNS lookup or LCE client connect) is seen. Having an event when a new host first comes online can be very useful; this event can be used, for example, to launch a vulnerability scan on the new host.

For systems like servers that are always on, there will be a spike around midnight for these events. Other computers may start out their day at various times. This dashboard can be used to look for anomalies such as systems or users coming online at unexpected times, unknown systems or users popping up, or unexpected activity blackouts from known systems.

The corresponding reports are the Daily Host Alerts Report, Daily Host Alerts Report: Users Accessing Hosts, and Daily Host Alerts Report: Hosts Accessed by Users.

The dashboard and its components are available in the SecurityCenter Dashboard app feed, an app store of dashboards, reports, and assets.

The dashboard requirements are:

  • SecurityCenter 4.7
  • LCE 4.2.1

Listed below are the included components:

Daily Host Alerts Trend (Last 5 Days)
This component presents a line graph of Daily_Host_Alert events by time for the last 5 days.

Daily Host Alerts (Last 5 Days)
This component presents a table of Daily_Host_Alert events for the last 5 days, displaying the event time and associated host IP address.

Daily Host Alerts by User (Last 5 Days)
This component presents a table of Daily_Host_Alert events by user for the last 5 days, displaying the user associated with the event and trending data.

New Hosts (Last 5 Days)
This component presents a table of new hosts discovered in the last 5 days. These hosts were discovered not with the Daily_Host_Alert event, but instead with the PVS New_Host_Alert and LCE New_MAC events. (The New_MAC event records the first time a new MAC address is ever seen on the network; the New_Host_Alert event records the first time a new IP address is ever passively detected. These events are generated for any new host seen on the network, whereas the Daily_Host_Alert event is only generated for hosts in the “include-network” range.) This table can be used to correlate discovered hosts with the Daily_Host_Alert events.

New Users (Last 5 Days)
This component presents a table of new users discovered in the last 5 days. These users were discovered not with the Daily_Host_Alert event, but instead with the LCE New_User and New-Network-User events. (The New-Network-User event records the first time a new user is ever seen on the network; the New_User event records every time a user logs in to a new host and/or a new account type on a host.) This table can be used to correlate discovered users with the Daily_Host_Alert events.