Quantcast
Channel: THWACK: All Content - All Communities
Viewing all articles
Browse latest Browse all 19875

Newb question - search -> rule?

$
0
0

Hi,

 

I am trialling log management solutions at the moment.

 

I've got an example search configured looking for windows events which relate to account enabled or disabled for those accounts with fire in the name.

 

Is there a way to easily take this and create a rule from it?

 

( EventInfo = "User account disabled \"*fire*\"" ) OR ( EventInfo = "\"Account Enabled \\\"*fire*\\\"\"" )

 

Thanks


Viewing all articles
Browse latest Browse all 19875

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>