The Users Page

Introduction

The Users page helps administrators review user activity detected in their environment. From this page, you can identify active users, review login activity, determine which endpoints users have accessed, and investigate user-related activity across your organization.


This article covers the following topics: 


Understanding the Users Page

The Users page, found in the sidebar's Users section, displays all users recognized by Field Effect within your environment.


 

List View

The main view is presented as a list, with:

  • Each row representing a user
  • Each column displaying information about that user


By default, the following columns are available:


ColumnDescription
User NameThe detected username.
Active Host CountNumber of currently active hosts associated with the user.
All Host CountTotal number of hosts associated with the user.
Installed Host CountNumber of hosts with Field Effect software installed that are associated with the user.
First Seen (UTC)When the user was first observed in the environment.
First Login (UTC)The user's earliest recorded login.
Last Login (UTC)The user's most recent recorded login.
SIDThe user's Security Identifier (SID).


You can customize which columns are displayed to focus on the information most relevant to your investigation or audit.



Details View

Select a user from the list to open the Details pane at the bottom of the page. The Details pane provides additional information about the selected user and can help you investigate user activity within your environment.


To view the information in a larger format, select the Expand icon.



Search for Users

You are not limited to suggested values. You can enter your own search criteria where applicable.

Use the search bar to create custom searches and quickly locate specific users.


You can:

  • Perform keyword searches
  • Build searches using column values
  • Combine columns with logical operators and conditions


To create a search:

  1. Select a column from the search dropdown.
  2. Choose a logical condition, such as Contains, Is Not, or Is Null.
  3. Select one of the suggested values or enter your own search criteria.


For example, you can select:

  • Username
  • Contains
  • A specific username or partial username


The system will display matching results as you build your query.


 

Sort and Filter Results

The following sections walk through the page's sort and filter functionality. 



Sort Results

  • Select a column header to toggle between ascending and descending order.
  • Use the Order By option within search results to define a sorting preference.


Filter Results

  • Use Is Not to exclude specific values.
  • Use Is Null to display records that contain no value in the selected column.


As you build your filter, the search interface provides suggested values to help refine your query.


Filter by Date

When filtering date-based fields such as First Seen, First Login, or Last Login, use one of the following formats:

  • 2022-11-22T16:35:42
  • 2022-11-22T16:35:42Z
  • 2022-11-22T16:35:42.000
  • 2022-11-22T16:35:42.000+0000


Export Results

To export data from the Users page, select the Export CSV icon.


You can export:

  • All users in the environment
  • A filtered set of results based on your current search criteria


Exporting results can be useful for:

  • Security audits
  • Compliance reporting
  • Offline analysis
  • Sharing investigation findings with other team members




Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article