Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Search pattern for file audits on specific server not carried out by one of four accounts

$
0
0

One thing that just came to mind - if your file audit alerts are the subtypes (FileWrite, FileRead, FileAuditFailure, etc) and not just the parent FileAudit event itself, you'll want to use the "File Audit Events" event group instead of using the specific File Audit event itself. That way all of the subtypes are also included.

 

File Audit Events.InsertionIP = system1

AND

File Audit Events.SourceAccount != account1

AND

File Audit Events.SourceAccount != account2

etc

 

NOTE: I just did this myself and it seems to be the not equals that is causing some difficulty. It DOES work in filters and DOES work in rules, but is not working in nDepth searches. Still doing some digging as to what's happening.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>