Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Alerts on Event Viewer items

$
0
0

Can you be a little more precise on what events you need?  The codes 4099 and 4098 could appear in multiple logs (System, Security, Application, etc) or from multiple applications and mean different things based on what is generating them and where they occur.

 

Assuming you mean these:

 

http://technet.microsoft.com/en-us/library/cc774453%28v=ws.10%29.aspx

GPP Local Users and Groups fails with Event ID 4098 on Windows 8 and Windows Server 2012

 

I'd suggest that you run a search like this for the 4099:

 

2014-12-15 07_40_28-SolarWinds Log and Event Manager Console.png

 

And like this for the 4098:

 

2014-12-15 07_40_55-SolarWinds Log and Event Manager Console.png

 

This is all predicated on your:

  • Having the Agent running on machines where this event has occurred in the past
  • Having the Connectors setup to capture those events (though these examples use Connectors the Windows Agent sets up by default)
  • That you're searching a time-range where the event occurred
  • That your connectors have their default Tool Aliases

 

Once you know what the events are normalized as, building a rule to look for those precise events and send an e-mail or other alert should be pretty simple.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>