Syteca alerts: real-time and batched detection of forbidden user activity — across Windows, macOS, and Linux Clients — with email, tray, on-screen warning, automatic blocking, or process kill response actions.
Recording user activity is useful in retrospect — to investigate something that already happened. The harder problem is detection in real time: knowing the moment a user does something forbidden, while the recording is still being captured, so the security team can intervene before the data is gone. Most monitoring tools eventually surface forbidden activity in a report somewhere; the question is how fast and how loudly.Syteca alerts sit between the two: a flexible rule engine with parameters covering Windows, macOS, and Linux activity (applications, URLs, keystrokes, clipboard, file uploads, Linux commands, Active Directory group membership), four response actions (email, tray notifications, on-screen warning, automatic block / process kill) — all configured inside the same Management Tool, against the same Client agents you’ve already deployed, with no second product required.
Use Syteca alerts when you need to:
Detect insider threats in real time — credential abuse, data exfiltration, privileged action outside normal patterns.
Automate incident response by combining alert detection with user blocking or process kill — no human latency.
Surface compliance violations (PCI DSS forbidden data access, HIPAA unauthorized PHI viewing, ISO 27001 access policy deviations) as both audit trail and active intervention.
Layer defense-in-depth with UEBA: UEBA catches deviation from normal, alerts catch defined forbidden activity. Together they cover both halves of the detection space.
Get started without designing rules from scratch — Syteca ships with default alerts for fraud indicators, data leakage, illicit websites, and non-work activity.
Pair it with Block on alert — alerts handle detection; blocking handles immediate response. The complete detect-and-stop pipeline lives in one platform.
Alerts have two complementary uses:
Use
Pattern
Immediate response
Detect a forbidden action and respond at machine speed — email + tray + on-screen warning + automatic block or process kill.
Delayed response
Detect a batch of forbidden actions across many Clients, then analyze and respond. Tune the Global Alert Settings to control batching.
This page covers managing alert rules. For the catalog of alert rules that ship preconfigured with Syteca, see Default alerts. For the rule-engine reference (parameters, comparison operators, regex, logical operators), see Alert rules. For triaging alert events after they trigger, see the Alerts events tab.
Optionally enter a Description (up to 500 characters).
Select the risk level — Normal, High, or Critical.
3
Define the rules
In the Rules section, define what triggers the alert. Each rule has:
A parameter (e.g. URL, Application, Keystrokes, Command, etc.).
A comparison operator (Equals, Like, Not equals, Not like, Matches Regex).
A value to compare against.
Click + Or or + And to add additional rules.
For the full reference of available parameters, comparison operators, regex syntax, and worked rule examples, see Alert rules.
When multiple rules are defined in one alert, rules of the same type combine with OR logic, and rules of different types combine with AND logic. See Logical operators for the full semantics.
4
Assign Clients
In the Assigned Clients and Assign Client Groups sections, click Add to pick the Clients and Client groups the alert applies to.
Use the Search box to find specific Clients or groups by name.
5
Configure actions
In the Actions section at the bottom, choose one or more response actions:
Action
Effect
Send emails to
Email recipients when the alert triggers. Separate addresses with semicolons.
The Rules section of an alert — define what activity triggers the alert by combining parameters, comparison operators, and values with + Or / + And.
One alert
Multiple alerts (Manage Multiple)
On the Alerts page, click the Edit Alert icon next to the alert. Edit the properties, rules, assigned Clients, and actions the same way as when adding it. Click Finish to save.
1
Open Manage Multiple Alerts
Click the Alerts drop-down arrow at the top of the page, then select Manage Multiple Alerts.
2
Select alerts
On the Alert Selection tab, select the checkboxes next to the alerts to edit. Optionally click Enable/Disable next to specific alerts on the right. Click Next.
3
Assign Clients
On the Assigned Clients tab, select the Clients and Client groups to assign these alerts to. Click Next.
4
Set actions
On the Actions tab, configure notifications and additional actions as in Add an alert Step 5. Click Finish.
To stop receiving notifications about an alert without deleting it, disable it instead.
One alert
Multiple alerts (Bulk Action)
Multiple alerts (Manage Multiple)
Open the alert with the Edit Alert icon, then deselect the Enabled checkbox in the Properties section. Click Finish. Re-select the checkbox to re-enable.
On the Alerts page, select the checkboxes next to the alerts. Click Bulk Action in the top left, then choose Enable or Disable.
Open the Alerts drop-down → Manage Multiple Alerts. Click Enable/Disable next to specific alerts, or use the Enable All / Disable All column header to apply to all.
Three different entry points for the same operation — pick whichever workflow fits where you are in the product.
While editing one alert
While managing multiple alerts
While editing a Client / Client group
1
Open the alert
Click the Edit Alert icon next to the alert on the Alerts page.
2
Pick Clients
Scroll to the Assigned Clients section and select the Clients and Client groups.
3
Save
Click Finish.
1
Open Manage Multiple Alerts
Click the Alerts drop-down → Manage Multiple Alerts.
2
Select alerts
On the Alert Selection tab, pick the alerts to assign. Click Next.
3
Pick Clients
On the Assigned Clients tab, pick the Clients and Client groups. Click Next, then Finish.
Use the Search box at the top and Apply Filters button to find specific Clients or groups by name.
1
Open the Client
Click Clients in the left navigation. Click the Client name in the Client Name column — or select the Client Groups tab and click a group name in the Client Group Name column.
2
Pick alerts
On the Editing Client (or Editing Client Group) page, select the Assigned Alerts tab and pick the alerts to assign.
Alerts can be exported to an XML file (for backup, version control, or migration between Syteca deployments) and re-imported elsewhere.
Export
Import
1
Open Export Alerts
Click the Alerts drop-down at the top of the page, then select Export Alerts.
2
Pick alerts
On the Export Alerts page, select the checkboxes next to the alerts to export.
3
Download
Click Export in the bottom right. The Alerts.xml file containing the selected alerts and their parameters downloads to your computer.
1
Open Import Alerts
Click the Alerts drop-down, then select Import Alerts.
2
Pick a file
On the Import Alerts page, click Choose File and select the .xml file. Click Open, then Add to the right of the file name.
3
Configure imported alerts
Imported alerts are added enabled by default, but not assigned to any Clients. Click Define Imported Alerts Settings to assign them and configure notification options.
If Syteca already contains an alert with the same ID as one being imported, the existing alert is updated with the imported parameters.
Open the alert with the Edit Alert icon, then click Delete Alert in the bottom left of the Edit Alert page. Click Delete in the confirmation.
On the Alerts page, select the checkboxes next to the alerts. Click Bulk Action in the top left, choose Delete, then click Delete in the confirmation.
When you delete an alert, all alert events that were triggered by it are no longer marked as alert events. The session recordings remain, but the alert markers are removed.
Select multiple alerts with the checkboxes (or the Select All checkbox in the column header), then click Bulk Action in the top left for these options:
Enable / Disable — turn the selected alerts on or off.
Global Alert Settings control email batching across all alerts — useful to prevent alert fatigue when a single rule (or related rules) fires repeatedly within a short window.
1
Open Global Alert Settings
Click the Alerts drop-down at the top of the Alerts page, then select Global Alerts Settings.
2
Configure the minimum interval
Set Minimal interval between the same alert events in one session (min) — for example, set to 10 so that if a user opens MS Word and keeps using it, you receive one notification every 10 minutes instead of a stream of them.
3
Choose batching mode
Pick one:
Send notifications on every alert event — immediate, one email per event.
Send batch notification every (min) — accumulate events in time windows; one email per window.
With batched mode, the timing window starts from Application Server startup. Notifications then send at the configured interval.
Once an alert triggers, the event information appears in five different places across the Management Tool. Choose the surface(s) that fit your workflow:
Alert names appear in the Alert/USB Rule column of the Metadata grid, color-coded by risk level. The Alert ID appears in the Details area when the record is selected.
Aggregate views of alerts triggered within a time period, including counts and lists of events.
Email notifications
If Send emails to is enabled on the alert, each email contains Alert ID, Alert name, Description, Who/What/When/Where, the rule parameter and value, and an Open Session link into the Session Viewer at the alert moment. Customize subjects on the Configuration → Customization tab, Custom Email Subjects section.
If Show warnings in the Syteca Tray Notifications application is enabled, pop-ups appear in the Windows system tray. The Tray Notifications Journal keeps history and links each event to the Session Viewer.