Hey. My goal - Monitoring of specific events on a file server. I want to be notified when there is "audit failure" and "success audit" for a specific folder on the server. My sensors are configured wmieventlogsensor-Security Audit Failure / Security Audit Success. But I receive messages all over the Security Audit Failure / Security Audit Success, and I need for a specific folder \ path. Where in the sensor settings can I specify what that value to the sensor wmieventlogsensor tracked desired me events?


Article Comments

Hello,

In order to filter for a specific folder \ path you can use in the sensor settings Filter by Category or Event Source.


Aug, 2016 - Permalink