Quantcast
Channel: THWACK: Popular Discussions - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5911

Is it possible in a rule/filter to create a correlation/condition in which the text of one event field is contained within anaothe field?

$
0
0

Okay,

     I know this may sound a bit confusing.  Here's the specifics of what I am attempting to do......

 

     For the UserLogon Event; I want to see if the text contained in the DestinationAcoount Fieldis or is not contained within the EventInfo Field.

 

     This is related to the Windows Security Event ID:4624. (UserLogon).  For example, the DestinationAccount field would show the text "someuser", while the EventInfo field would show "Logon ""somedomain\someuser"".

 

     Is it possible in a rule/filter syntax to see if "someuser" is contained within "somedomain\someuser"?  I attempted to write a filter(unsuccessfully using the following syntax...

 

         


Viewing all articles
Browse latest Browse all 5911

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>