Hello! I am having problems when configuring the output of values from the log to the trigger.
We have a log windows event viewer and event 4720 (user creation):
I want the following values to be displayed in the trigger name: Administrator created the user Username.
Previously, I used {{ITEM.VALUE} .iregsub to grab values from the log, but now I can't do that because the Security ID, Account Name and Account Domain values are the same for both the user who creates the account and the created user.
Please tell me how to be in such a situation when it is necessary to display such values? Sorry for my english.
We have a log windows event viewer and event 4720 (user creation):
A user account was created.
Subject:
Security ID: Contoso\Administrator
Account Name: Administrator
Account Domain: Contoso
New Account:
Security ID: Contoso\Username
Account Name: Username
Account Domain: CORP
Subject:
Security ID: Contoso\Administrator
Account Name: Administrator
Account Domain: Contoso
New Account:
Security ID: Contoso\Username
Account Name: Username
Account Domain: CORP
Previously, I used {{ITEM.VALUE} .iregsub to grab values from the log, but now I can't do that because the Security ID, Account Name and Account Domain values are the same for both the user who creates the account and the created user.
Please tell me how to be in such a situation when it is necessary to display such values? Sorry for my english.
Comment