Quantcast
Channel: THWACK: Message List - Kiwi Syslog
Viewing all articles
Browse latest Browse all 2141

Re: Windows failed logins tracking

$
0
0

How are you determining that nothing is reaching the syslog server?

 

If you have not already done so, create a new rule with a filter that includes either the event IDs or message text snippet(or both) that you want to capture.  Then add an action to display to a  specific display ID( 02 for example).

 

Are you using a Win2008 or Win2012 AD server? If so make sure you are looking for the 'new' event ID(4625).

 

If your filter is working you will see the events in that console view.


Viewing all articles
Browse latest Browse all 2141

Trending Articles