Hi,
I want to ask regarding the possibility to create use case (to get alert) where we want to track situation where some specific user did not logged into the system (for example on Windows machine) more then 15 days.
Is it possible to be done using Netwitness ESA correlation engine?
Regards
Hi Petar Nikovic,
Please Create a list with users in Reports->List
Create a rule with Where User = <the list created> Run for last 15 days.
Then Will have to compare the results with list to find did not logged in for 15 days.
ESA used only for real-time correlation.