|
|
|
Forum Member
      
Group: Forum Members
Last Login: 2/24/2012 7:49:27 PM
Posts: 26,
Visits: 12
|
|
Randy,
In my SIM I'm seeing a ton of EVID 4762 being generated as events. Are there are other EVIDs that would take precedence over 4672 and as long as they're being flagged as events that would allow me to suppress 4672 as an event but still capture the log for forensic purposes?
Thx,
Jeff
|
|
|
|
|
Security Log Nerd
      
Group: Administrators
Last Login: 4/16/2009 1:11:51 PM
Posts: 49,
Visits: 0
|
|
| At the server level you can disable the Special Logon subcategory. As an an alternative most SIEM (SIM) software allows you to filter it out by the event number
|
|
|
|