Ad Widget

Collapse

Monitoring of Logon failure - Windows

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • vanesen
    Junior Member
    • Feb 2022
    • 1

    #1

    Monitoring of Logon failure - Windows

    Hi All,

    I need some help.

    I have already created a new template and also the item with the following key
    eventlog[Security,,,,4625,,skip]
    But i have some questions :

    1 ) Do i really need to create a trigger?
    2) And do i need to download a new template for Windows Event Log?

    I tried creating the following trigger but it doesn't work.

    ((find(/Windows Failed Logon/eventlog[Security,,,,4625,,skip],,"regexp","{HOST:eventlog[Security,,,,4625,,skip].logeventid(4625"))<>0)

    Thanks and Regards,

    Vanesen.
  • Illya
    Junior Member
    • Jul 2023
    • 1

    #2
    logeventid(/your machine/eventlog[Security,,,,4625,,skip])=1

    Comment

    Working...