Skip to main content

Predefined Investigations Page

The Predefined Investigations page in the Investigations interface provides a list of saved out-of-the-box investigations with applied filters for Computers, Groups, iNetOrgPerson, and User activity reports.

Click Investigate in the application header bar to open the Investigations interface. Then click Predefined Investigations in the navigation pane. This expands the menu to display the folders containing predefined investigations. Expand a folder to view the investigations under it. To get a list of all the predefined investigations in the adjacent pane, hover your mouse over the Predefined Investigations option and click the icon that is displayed.

Investigations interface on the Predefined Investigations page

The table displays the list of investigations with the following columns:

  • Name – The name of the investigation
  • Favorite – The check mark indicates that the investigation has been tagged as a favorite for the logged in user

Click an investigation to view it. You can run the query, modify the configuration, add a subscription, or export the report. See the Investigation Options topic for additional information on saved investigation options.

Every report generated by an investigation query displays the same type of information. See the Investigation Reports topic for additional information.

By default, these investigations are grouped in subfolders. Each subfolder page has the same table as the Predefined Investigations page, scoped to the investigations within that folder.

Computers Folder

By default, this folder contains the following saved investigations:

InvestigationDescriptionFilters
Computer AddedCreated when a computer is addedTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Create AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = computer
Computer DeletedCreated when a computer is deletedTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Delete AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = computer
Computer DisabledCreated when a computer is disabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Disabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = computer
Computer EnabledCreated when a computer is enabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Enabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = computer
Computer Password ChangedCreated when a computer password is changedTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Password Changed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = computer

You can save additional investigations to this folder.

Groups Folder

By default, this folder contains the following saved investigations:

InvestigationDescriptionFilters
Group AddedOccurs when a group of any type is createdTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Create AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = group
Group DeletedCreated when a group is removed / deletedTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Delete AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = group
Group Member AddedCreated when a member is added to a groupTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Group Members Added AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = group
Group Member RemovedCreated when one or more members of a group are removedTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Group Members Removed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = group
Group MovedOccurs when a group is moved from one container to anotherTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Object Move AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = group

You can save additional investigations to this folder.

iNetOrgPerson Folder

By default, this folder contains the following saved investigations:

InvestigationDescriptionFilters
iNetOrgPeson Account DisabledCreated when an iNetOrgPerson account is disabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Disabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = inetOrgPerson
iNetOrgPeson Account EnabledCreated when an iNetOrgPerson account is enabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Enabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = inetOrgPerson
iNetOrgPeson AddedCreated when an iNetOrgPerson User account is addedTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Create AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = inetOrgPerson
iNetOrgPeson DeletedCreated when an iNetOrgPerson is deletedTwo filter statements set: - Attribute 1 = Event Operation - Operator 1 = Equals - Filter 1 = Active Directory Delete AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = inetOrgPerson
iNetOrgPeson Password ChangedCreated when the password is reset or changed by an administratorTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Password Changed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = inetOrgPerson

You can save additional investigations to this folder.

Users Folder

By default, this folder contains the following saved investigations:

InvestigationDescriptionFilters
User Account DisabledCreated when a user account is disabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Disabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user
User Account EnabledCreated when a user account is enabledTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Enabled AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user
User Account LockedCreated when a user account is lockedTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Locked AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user
User Account UnlockedCreated when a user account is unlockedTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Account Unlocked AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user
User Password ChangeCreated when a user performs a password resetThree filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Active Directory Password Changed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user AND - Attribute 3 = Perpetrator - Operator 3 = Equals - Filter 3 = nt authority\anonymous logon
User Password Reset and ChangeCreated when a user resets their password or when an administrator changes their passwordTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Password Changed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user
User Primary Group ChangedCreated when a user's group is changed typically from Domain Users to another groupTwo filter statements set: - Attribute 1 = Event Sub-Operation - Operator 1 = Equals - Filter 1 = Primary Group Changed AND - Attribute 2 = Object Class - Operator 2 = Equals - Filter 2 = user

You can save additional investigations to this folder.