Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: How to monitor local user accounts

$
0
0

When you perform one of those actions on your router (add, modify, delete) are you able to see the event in nDepth?

 

If you are able to see the event, but the rule didn't fire then it may be logging as a slightly different event than what the rule is looking for.  For Windows you'll typically see NewDomainMember or NewGroupMember depending on what you're doing with the account, but for a router you may see something entirely different, SystemStatus or PolicyModify or even other events.

 

As a result if you're using a template rule it may not match up directly.  You could add the event types to your existing rule or you could create a new rule for the events that you're seeing.

 

If you're not seeing the events at all, then you will want to verify that those particular events are reaching the LEM (maybe you need to adjust the trap level, for instance), before they would be able to trigger a rule to fire.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>