Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: LEM shutdown Windows Machine at admin logon failure

$
0
0

If you go to EXPLORE --> nDEPTH, and search for events matching the rule correlation, what do you get?  What do these events have in the Destination Machine field?  Does it all look correct?

 

When you say you don't see the rule firing, you're not seeing events in the Rule Activity filter?  If you do an nDepth search for InternalRuleFired where the EventInfo contains *NAMEOFRULE*, do you get any results at all in the last few days?


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>