Example: Populating Active Lists with Trend Results

Suppose you want to monitor top failed user logins daily and send that data to an active list. (You could then configure rules to interact with the active list and trigger an alarm based on some threshold; for example, a single user with a certain number of failed logins per day.) To do this, you could create an active list with fields that map to a trend that monitors “top users with failed logins”.

To see the fields in this trend:

Your active list must have one or more of the trend's fields to capture relevant data in the list, as we’ll show in the next section where we define the trend.

To continue with the example, we could create a fields-based active list with fields that map to the trend “Top Users with Failed Logins per Day” as follows.

 

Name

Type

Key Field

User Name

String

This is the key field.

Day and Time

Date

 

Number of Failed Logins

Long

 

When the trend runs, it populates the active list with data on top users with failed logins by user name, and list the count of failed logins for each user along with date/time information. This active list could be used as the basis for rules, filters, active channels, and so on.

Notes on Trend Action Behavior