Quantcast
Channel: THWACK: Message List
Viewing all articles
Browse latest Browse all 20616

Re: Search pattern for file audits on specific server not carried out by one of four accounts

$
0
0

I know, replying to myself. So far my testing has yielded:

  1. This works as described in filters and rules
  2. Equals works great in nDepth but not equals with a field seems to be dysfunctional (differently functional?)
  3. Using the "User Name" refine field (only exists in nDepth) with != does seem to work. (User Name searches across all account fields, using a field directly just searches that one field... so it's not precisely equal but it's worth a shot)

 

So, try reconstructing your search with:

File Audit Events.InsertionIP = server1

AND

User Name != user1

AND

User Name != user2

AND

User Name != user3

 

You might have to run the first search (File Audit Events.InsertionIP=server1) then drag the user name field into the search bar from the refine fields on the left to get it to add.


Viewing all articles
Browse latest Browse all 20616

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>