Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Logs for Clearing/stopping Audit logging

$
0
0

Hi,

 

I have installed LEM and configured Windows Application, Security, Active Response and Systems logs.

 

I need to find the logs if someone stop. clear or access the Logs in Windows machines, where agents installed.

 

I tried to clear the logs and also stopped the event viewer service. Both event generated logs in the respective machines but I dont see them in the "ndepth".  Am I doing something wrong.

 

By the way connector output is set to Alert i.e. not to Alert and ndepth-- will this affect it.

 

Is there any Rule to see the logs for Audit stop/start/access ????

 

Please advise.

 

Regards


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>