Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Trouble creating a rule to block access to a process

$
0
0

hi Will,

 

Your rule looks right. Are you seeing ProcessStart LEM Events like below if you run an nDepth query "Event Name" = ProcessStart ?

LEM-ProcessStart.png

 

If not - as evileyes07 said, you need to first of all ensure there is an Agent installed on this computer. You will also need to ensure that the Process Tracking is enabled to generate a Windows Event log. See below

SolarWinds Knowledge Base :: Audit Policy and Best Practice


Viewing all articles
Browse latest Browse all 5385

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>