Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Using LEM to log and report OWA authentication request events

$
0
0

Update: Since posting, I am able to perform an nDepth search to find failed authentication requests to OWA.

 

Refine the query with the following conditions:

WebTrafficAudit.AlertActivityType=HTTP-401 AND WebTrafficAudit.URL=<URL> (e.g. 192.168.0.1/owa/auth.owa)

nDepth Conditions OWA fail Auth.png

Specify a time period and run the search.

 

 

 

I am yet to distinguish auth success events generated by users logging into OWA and not general navigation through OWA. Any help on refining my results to show only these events would be highly appreciated.

 

 

-Garreth


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>