Possible to suppress EVID 4672? Expand / Collapse
Author
Message
Posted 1/5/2012 10:04:52 AM
Forum Member

Forum MemberForum MemberForum MemberForum MemberForum MemberForum MemberForum MemberForum Member

Group: Forum Members
Last Login: 2/24/2012 7:49:27 PM
Posts: 26, Visits: 12
Randy,

In my SIM I'm seeing a ton of EVID 4762 being generated as events. Are there are other EVIDs that would take precedence over 4672 and as long as they're being flagged as events that would allow me to suppress 4672 as an event but still capture the log for forensic purposes?

Thx,
Jeff
Post #889
Posted 2/20/2012 2:32:04 PM
Security Log Nerd

Security Log NerdSecurity Log NerdSecurity Log NerdSecurity Log NerdSecurity Log NerdSecurity Log NerdSecurity Log NerdSecurity Log Nerd

Group: Administrators
Last Login: 4/16/2009 1:11:51 PM
Posts: 49, Visits: 0
At the server level you can disable the Special Logon subcategory. As an an alternative most SIEM (SIM) software allows you to filter it out by the event number
Post #919
« Prev Topic | Next Topic »


Permissions Expand / Collapse

All times are GMT -5:00, Time now is 9:54am