Hi All - was wondering if anyone can help on the following:
event ID 4624 : this event logs everything that speaks to the domain, I just want to log user who below to the DD1 domain and forget and drop the rest of the events
below is an event of computer generated 4624 ID, this is the message part of the log
Is there anyway I can block account names when they are Server names, or for starters block all Account domain that are ADD and accept all domains that are FFE
this is my spacing, you are correct, the ymls are well tricky when it comes to spaces - still not working, spaces are still incorrect ? This is view in text pad, any pointers as my database is filling up with unwanted 4624 events ?
Hi James
I'm not shure about the sintax you are using...
Which version of winlogbeats do you have? seems like mixing syntax from different versions.,
What does this line means?
Here is my working config.
I drop events 4624, 4634 and 4672 when username start with $ or is a DWM-x or is SYSTEM and drop events 4674,4985,4778,4779,4647,...4766 (because I'll analyze those events later)
Hi @james_007 ,
I have tested what you want to do and it works.
I've configure winlogbeat to send only events 4624 and 4672 and drop the events 4624 under certain conditions. For testing I drop the event 4624 for user at_adm
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.