Quantcast
Channel: THWACK: Message List
Viewing all articles
Browse latest Browse all 20958

Newb question - search -> rule?

$
0
0

Hi,

 

I am trialling log management solutions at the moment.

 

I've got an example search configured looking for windows events which relate to account enabled or disabled for those accounts with fire in the name.

 

Is there a way to easily take this and create a rule from it?

 

( EventInfo = "User account disabled \"*fire*\"" ) OR ( EventInfo = "\"Account Enabled \\\"*fire*\\\"\"" )

 

Thanks


Viewing all articles
Browse latest Browse all 20958

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>