Quick Links

User activity (UEBA) in Hearth

Overview

Hearth’s user and entity behavior analytics (UEBA) is on the User activity page, which provides behavior analytics for the people in your workspace. User activity learns the normal sign-in and admin-action pattern of each person, compares each person against their peers, and raises an alert when the behavior of someone breaks the pattern.

When an event warrants a response, Hearth proposes an action for you to review. Nothing runs until a person confirms it.

Note: For the most useful insights, connect at least one identity source and audit-log source, such as your identity provider or Microsoft 365 in Blumira as well as in Hearth, so that Hearth has sign-in and administrator activity to learn from. An identity source configured in Hearth will supplement the data with organizational units (departments/teams), but will not provide as many valuable insights on its own.

How it works

User activity builds a baseline for each person from their sign-in and audit activity as that activity flows into Blumira. The baseline includes typical hours, source IP addresses, countries, and admin actions.

User activity does not measure a person only against their own history. Where your identity source groups people, User activity also compares each person against their named peers, which are the members of their department or organizational unit. As a result, Hearth explains an alert in plain terms, such as a sign-in that is rare for a department or a country that no peer signs in from, rather than as an opaque score.

When behavior breaks the pattern, User activity raises an alert. From any alert, you can open a Smart Timeline and hand the event to Hestia for investigation. Where an action is warranted, Hearth builds a proposed action for your review.

Important: Hearth does not block a risky user on its own. User activity proposes an action, and a person confirms the action before anything runs.

Elements of the User activity page

The following table describes the elements of the page:

ElementDescription
Alert listDisplays the recent activity alerts, such as Off-hours login, First-ever admin action, and Login from a new country.
Peer comparisonAppears on the row of a person when a peer signal exists, and displays how that person compares against their peers.
Watchlist star (☆)Pins a person to your watchlist. A pinned person moves to the top of the list and stays visible during quiet periods.
Pin all adminsAppears when your watchlist is empty and pins every privileged account in one click.
Person profileOpens the detail view for one person, which includes their Smart Timeline.
Smart TimelineDisplays a chronological, cross-source view of the activity of one person, with the noise reduced. The timeline contains meaningful events, such as logins, privilege changes, and unusual access, rather than every raw log line.
Investigate and Investigate with HestiaOpen the alert or the person as a Hestia conversation with the supporting evidence.
Run baseline nowBuilds a baseline from recent activity immediately.
Clear baseline dataFound within the actions menu, this option clears the baseline if one exists.

Building a baseline

Baselines build automatically as sign-in and audit activity flows into Blumira. To build a baseline from recent activity immediately, click Run baseline now.

Reviewing activity alerts

To work the alert list:

  1. Navigate to User activity.
  2. Review each alert, such as Off-hours login, First-ever admin action, or Login from a new country.
  3. Review the peer comparison on the row of each person, where a peer signal exists.

Adding a person to your watchlist

To keep a specific person in view, do the following:

  1. On the row of that person, click the star (☆). Hearth adds the person to your watchlist and moves them to the top of the list.
  2. (Optional) If your watchlist is empty, click Pin all admins to start with your privileged accounts.

Opening a Smart Timeline

A Smart Timeline helps you investigate a flagged event and respond to a request from IT or HR.

To review what a person did during a window, do the following:

  1. Click the name of the person to open their profile.
  2. Review the Smart Timeline, which displays the meaningful events of that person in chronological order across every source.

Investigating an alert

To hand an alert to Hestia for investigation, do one of the following:

  • On the alert, click Investigate.
  • On the profile of a person, click Investigate with Hestia.

Review the resulting Hestia conversation, which contains the supporting evidence.

Acting on a proposed action

When Hearth proposes an action, review the action and confirm it. An automation proposes an action for review, and it never runs on its own.

Troubleshooting common issues

IssueWhat to do
No alerts appearConfirm that your identity sources and audit-log sources, such as your identity provider or Microsoft 365, are connected and actively sending information into Blumira. User activity cannot baseline behavior that it never sees.
A person displays no peer comparisonPeer context appears only when a qualifying peer group, such as a department or an organizational unit, contains enough members for a comparison. Without peers, Hearth displays the own-history baseline of that person and omits the peer line rather than displaying an inaccurate one.
The “Run baseline now” button does not appearThe manual baseline requires the analyst role or higher. Baselines still build automatically for every role, and viewing is open to every role.
The User activity page does not appear in the navigationThe page requires the “View exposure” permission. Confirm the permissions included in your role with an administrator.