Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Rule with logon and shift does not work - please help

$
0
0

Assuming that "SpecialClients" is a User Defined Group with a list of hostnames (complete with the necessary wildcards), and that you want an alert when someone tries to log IN to a SpecialClient and not when someone tries to remotely log into another system FROM a SpecialClient, you need to use "UserLogon.DestinationMachine" is contained in "SpecialClients."

 

This also assumes that "SpecialClients" have the LEM Agent installed and an Audit Policy that will generate the needed UserLogon events in place.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>