Quantcast
Channel: THWACK: Message List - Kiwi Syslog
Viewing all articles
Browse latest Browse all 2141

Re: Question about filtering Windows Security Audit Successes.

$
0
0

These kind of messages i dont need to see, Audit Success. Failures will show up as Criticals anyway. Priority filtering doesnt seem to work, so i tried text to no avail.

 

Oct 27 17:14:53  MSWinEventLog 5 Security 6181 Tue Oct 27 17:14:50 2015 4634 Microsoft-Windows-Security-Auditing N/A Audit Success  12545 An account was logged off.

 

 

Subject:

Security ID: xxxxxx

Account Name: xxxxxx

Account Domain: xxxxxx

Logon ID: xxxxxxx

 

 

Logon Type: 3

 

 

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.


Viewing all articles
Browse latest Browse all 2141

Trending Articles