Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Filter NT Authority\System

$
0
0

With that filter in place I am not getting File deletes. The source account is not SYSTEM here. Its a user.

I am trying to create a filter that shows file deletes, writes and creates but not show form EventInfo .TMP files, NT Authority\SYSTEM doing something to the file and ~$ files.

It seems like I cannot get the right combo down. Not even sure its possible. I know a lot of this spends on what Windows shows. I do see many people with the same questions

 

Screenshot_100215_040205_PM.jpg


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>