2012-05-03
09:08 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
crl-00103 will not fire - no alerts/views.
Hi I do not get any alarms/alerts when adding a local user to local group administrators when using CRL-00103. My copy of the correlation rule is as the original. I have manually set up a rule for all windows machines. Here I do get alerts for same behavior on windows machines. In my system CRL-00103 only has one circut with one statement. Value: "User.Management.Groups.Modifications.User Added" I figure that it might be wrong setup. How do I get a "fresh" copy of the correlation rule? Thank you
1 Reply
2012-07-16
03:58 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I'm guessing that that particular CRL doesn't cover the specific windows event ID you are looking for/at.
Go to Overview / System Configuuration / Messages / Manage Messages and then show all entries for Taxonomy/Event Category = "User.Management.Groups.Modifications.User Added" AND all of the Windows devices types like attached.
These are the messages that are included in that CRL. Otherwise, you need to make a copy of that CRL, which also includes your expected message ID.
