cancel
Showing results for 
Search instead for 
Did you mean: 

Users logged on over 12 hours

Morning All, quite new to this......I'm trying to set up a correlation rule that shows users logged on over 12 hours............thank you

 

1 Reply
Reliable Contributor brenta
Reliable Contributor
Report Inappropriate Content
Message 2 of 2

Re: Users logged on over 12 hours

You will need to have at least 2 events for this.

Often you can build these types of correlation rules by looking for the login event, and absence of the logout event. This requires a logout event in addition to the login. You will want to group by Source User.

Brent
More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator