Introduction
The Users page helps administrators review user activity detected in their environment. From this page, you can identify active users, review login activity, determine which endpoints users have accessed, and investigate user-related activity across your organization.
This article covers the following topics:
Understanding the Users Page
The Users page, found in the sidebar's Users section, displays all users recognized by Field Effect within your environment.
List View
The main view is presented as a list, with:
- Each row representing a user
- Each column displaying information about that user
By default, the following columns are available:
| Column | Description |
|---|---|
| User Name | The detected username. |
| Active Host Count | Number of currently active hosts associated with the user. |
| All Host Count | Total number of hosts associated with the user. |
| Installed Host Count | Number of hosts with Field Effect software installed that are associated with the user. |
| First Seen (UTC) | When the user was first observed in the environment. |
| First Login (UTC) | The user's earliest recorded login. |
| Last Login (UTC) | The user's most recent recorded login. |
| SID | The user's Security Identifier (SID). |
You can customize which columns are displayed to focus on the information most relevant to your investigation or audit.

Details View
Select a user from the list to open the Details pane at the bottom of the page. The Details pane provides additional information about the selected user and can help you investigate user activity within your environment.
To view the information in a larger format, select the Expand icon.

Search for Users
You are not limited to suggested values. You can enter your own search criteria where applicable.
Use the search bar to create custom searches and quickly locate specific users.
You can:
- Perform keyword searches
- Build searches using column values
- Combine columns with logical operators and conditions
To create a search:
- Select a column from the search dropdown.
- Choose a logical condition, such as Contains, Is Not, or Is Null.
- Select one of the suggested values or enter your own search criteria.
For example, you can select:
- Username
- Contains
- A specific username or partial username
The system will display matching results as you build your query.
Sort and Filter Results
The following sections walk through the page's sort and filter functionality.

Sort Results
- Select a column header to toggle between ascending and descending order.
- Use the Order By option within search results to define a sorting preference.
Filter Results
- Use Is Not to exclude specific values.
- Use Is Null to display records that contain no value in the selected column.
As you build your filter, the search interface provides suggested values to help refine your query.
Filter by Date
When filtering date-based fields such as First Seen, First Login, or Last Login, use one of the following formats:
- 2022-11-22T16:35:42
- 2022-11-22T16:35:42Z
- 2022-11-22T16:35:42.000
- 2022-11-22T16:35:42.000+0000
Export Results
To export data from the Users page, select the Export CSV icon.
You can export:
- All users in the environment
- A filtered set of results based on your current search criteria
Exporting results can be useful for:
- Security audits
- Compliance reporting
- Offline analysis
- Sharing investigation findings with other team members

Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article