hi,
we are monitoring security events using zabbix, and have found issue with our triger configuration:

If user is added at same time to many groups triger not trigered and we cannot search for logs in Monitoring -> Problems, but if we do right click on 4728 an event and do History -> Windows security (ID4728) we can see events, however if needed we cant search for events in this area (or we are missing how to serach them?)
Maybe we should change "PROBLEM event generation mode" to Multiple?
Thank you.
we are monitoring security events using zabbix, and have found issue with our triger configuration:
If user is added at same time to many groups triger not trigered and we cannot search for logs in Monitoring -> Problems, but if we do right click on 4728 an event and do History -> Windows security (ID4728) we can see events, however if needed we cant search for events in this area (or we are missing how to serach them?)
Maybe we should change "PROBLEM event generation mode" to Multiple?
PROBLEM event generation mode
please help.Thank you.
something must be tuned.
Comment