Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Reduce the number of SolarWinds TriGeo alerts from LEM

$
0
0

Sorry to be a newbie here. I found those rules. Many of them have "Machine Account"  listed. Is that the same as "Computer Account"? The rule that we seem to be getting the most false positives is similar to this:

 

computer account "fsbd\annextrain05$" changed: "-" at 2018-06-27 13:38:31.0

 

I had disabled the rule "Machine Account Properties Updated" as a test, but still get a lot of these.


Viewing all articles
Browse latest Browse all 5385

Trending Articles