> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Events, Alarms, and Notifications Created When a User's Status Changes

USM Anywhere enables you to configure <Tooltip tip="Alarms provide notification of an event or sequence of events that require attention or investigation.">alarms</Tooltip> to alert you when a user's entity or account status changes. USM Anywhere generates <Tooltip tip="Process of collecting all device status and event information and processing normalized events for evidence of vulnerabilities, possible attacks, and other malicious activity.">monitoring events</Tooltip> that display in the Events List View page. See [Events List View](../events/events-list-view) for more information. You can see two types of monitoring events related to User Behavior Analytics (UBA) user status: *user status changed* and *account status changed*. From these events, you may configure alarm rules to alert you when these status changes trigger events.

**To see events created when a user entity or account status changes**

1. Go to **Settings > System Events**.

2. Locate the Event Name filter and select either **User Status Changed** or **Account Status Changed**.

   <Frame>
     <img src="https://mintcdn.com/levelblue-5324744e/HGmP1muJoLfdGhKM/images/usm-anywhere/user-guide/user-behavior-analytics/userstatuschanged.webp?fit=max&auto=format&n=HGmP1muJoLfdGhKM&q=85&s=d4f2df483ff18e8e922c63a758ff4606" width="600" height="654" data-path="images/usm-anywhere/user-guide/user-behavior-analytics/userstatuschanged.webp" />
   </Frame>

   The result displays the filtered events.

3. Click the event to see its details.

**To create alarm rules when a user entity or account status changes**

1. Go to **Settings > Rules** and either:

   * Click **Create Orchestration Rule > Create Alarm Rule**.
   * Or click **Alarm Rules**, and then click **Create Alarm Rule**.

2. Populate the new alarm rule as described in [Alarm Rules](../rules-management/alarm-rules).

3. Under Rule Condition, use the Match drop-down list to select system\_events.

4. Click **Add Condition**.

5. Select **Event Name**, then **Equals**, and then either **User Status Changed** or **Account Status Changed**.

   <Frame>
     <img src="https://mintcdn.com/levelblue-5324744e/HGmP1muJoLfdGhKM/images/usm-anywhere/user-guide/user-behavior-analytics/user-status-rule-condition.jpeg?fit=max&auto=format&n=HGmP1muJoLfdGhKM&q=85&s=6694dbabcbe7de2f8f37592d14c3a689" width="1262" height="684" data-path="images/usm-anywhere/user-guide/user-behavior-analytics/user-status-rule-condition.jpeg" />
   </Frame>

6. Click **Save Rule**.

   The alarm rule has been created. You can see it from **Settings > Rules**. See [Alarm Rules from the Orchestration Rules Page](../rules-management/alarm-rules) for more information.

   <Warning>
     **Important:** It takes a few minutes for an orchestration rule to become active.
   </Warning>
