Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Filtering Certain Windows Security Events Before the LEM Agent Sends to the Manager

$
0
0

There hasn't been a list published, though the team may be looking at it. The only way you can sort of "reverse engineer" this list is in the connectors themselves. Each connector has patterns that match by event ID and source. It might be a little tough to extract that data, since some patterns are grouped together. There is a master list of which eventIDs are passed through the connector at the top of the connector (it's an element that looks like "eventIDs=" and may honestly just say eventIDs="all" - which means any eventID COULD pass into the connector, but there could ALSO be later filtering that drops it, which makes it complicated).


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>