Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: group changed "builtin\administrators" security enabled local group

$
0
0

You're on the right track with your thinking, so it's details. The default rule is correlating off the [Auditable Group Events] Event Group, so you'll want to use the same Event Group for the SourceAccount field.

 

I think something like this would work:

 

2015-08-21 14_33_57-SolarWinds Log & Event Manager.png


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>