Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Logon After Hours Alert Not Working

$
0
0

I would actually start at testing this as a filter. You can then see in real time which events arrive in based on the conditions you have in the filter.

Start with the very first condition, and add the UserLogon event conditions one by one.

Ie: Put in the first two userlogon conditions, as well as the very first business hours condition into a filter called: TESTFilter

Then check, what events are coming into this filter? Test by having someone generate those events.

Then work you way through there.

 

I'm suspicious of all the OR's stuck inside of a huge AND by the way. >.> vveerryyy suspicious.

Once you have it working in the filter on the monitor page, and are actively seeing ONLY those specific events you're looking for, then convert it back to a Rule.

 

What events do you see in the filter if you create a test one and put in only the first two conditions?


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>